{"source":"ghsa-maven","note":"Free 5-item preview. The full feed is $0.05/call at GET /v1/ghsa-maven/changes.","question":"Which new security vulnerabilities / CVEs affecting Maven/Java packages were published since T, and how severe (CVSS) are they?","sample":[{"source":"ghsa-maven","entityId":"ghsa:GHSA-mhww-p97m-3368","type":"advisory","title":"GHSA-mhww-p97m-3368 / CVE-2026-11400: AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance","summary":"HIGH severity. Affected: software.amazon.jdbc:aws-advanced-jdbc-wrapper.","significance":8,"detectedAt":"2026-07-18T23:42:10.777Z","effectiveDate":"2026-07-17T18:40:41Z","sourceUrl":"https://github.com/advisories/GHSA-mhww-p97m-3368","detail":{"severity":"high","cve":"CVE-2026-11400","packages":"software.amazon.jdbc:aws-advanced-jdbc-wrapper","cvss":8}},{"source":"ghsa-maven","entityId":"ghsa:GHSA-vg6x-6pg9-6qwg","type":"advisory","title":"GHSA-vg6x-6pg9-6qwg / CVE-2026-54076: ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)","summary":"HIGH severity. Affected: com.arcadedb:arcadedb-engine.","significance":8,"detectedAt":"2026-07-16T20:35:01.895Z","effectiveDate":"2026-07-16T20:08:24Z","sourceUrl":"https://github.com/advisories/GHSA-vg6x-6pg9-6qwg","detail":{"severity":"high","cve":"CVE-2026-54076","packages":"com.arcadedb:arcadedb-engine","cvss":8.1}},{"source":"ghsa-maven","entityId":"ghsa:GHSA-48qw-824m-86pr","type":"advisory","title":"GHSA-48qw-824m-86pr: ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read","summary":"HIGH severity. Affected: com.arcadedb:arcadedb-server.","significance":8,"detectedAt":"2026-07-16T20:35:01.895Z","effectiveDate":"2026-07-16T20:13:20Z","sourceUrl":"https://github.com/advisories/GHSA-48qw-824m-86pr","detail":{"severity":"high","cve":null,"packages":"com.arcadedb:arcadedb-server","cvss":7.7}},{"source":"ghsa-maven","entityId":"ghsa:GHSA-x9f9-r4m8-9xc2","type":"advisory","title":"GHSA-x9f9-r4m8-9xc2: ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)","summary":"HIGH severity. Affected: com.arcadedb:arcadedb-engine.","significance":7,"detectedAt":"2026-07-16T20:35:01.895Z","effectiveDate":"2026-07-16T20:15:36Z","sourceUrl":"https://github.com/advisories/GHSA-x9f9-r4m8-9xc2","detail":{"severity":"high","cve":null,"packages":"com.arcadedb:arcadedb-engine","cvss":null}},{"source":"ghsa-maven","entityId":"ghsa:GHSA-vwjc-v7x7-cm6g","type":"advisory","title":"GHSA-vwjc-v7x7-cm6g: ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js","summary":"HIGH severity. Affected: com.arcadedb:arcadedb-engine.","significance":7,"detectedAt":"2026-07-16T20:35:01.895Z","effectiveDate":"2026-07-16T20:17:42Z","sourceUrl":"https://github.com/advisories/GHSA-vwjc-v7x7-cm6g","detail":{"severity":"high","cve":null,"packages":"com.arcadedb:arcadedb-engine","cvss":null}}]}