Vulnlog / Vulnlog 0.17.0 (2026-08-24) 7 fixed: 4 low CVE-2024-12798 (low, also SNYK-JAVA-CHQOSLOGBACK-8539867, SNYK-JAVA-CHQOSLOGBACK-8539866) Improper neutralization of special elements vulnerability in Logback fix: Security scans now cover release artifacts only, where ktlint's logback is not present. ref: https://github.com/vulnlog/vulnlog/pull/253 CVE-2024-12801 (low, also SNYK-JAVA-CHQOSLOGBACK-8539865) Server-side request forgery (SSRF) vulnerability in Logback fix: Security scans now cover release artifacts only, where ktlint's logback is not present. ref: https://github.com/vulnlog/vulnlog/pull/253 CVE-2025-11226 (low, also SNYK-JAVA-CHQOSLOGBACK-13169722) External initialization of trusted variables or data stores vulnerability in Logback fix: Security scans now cover release artifacts only, where ktlint's logback is not present. ref: https://github.com/vulnlog/vulnlog/pull/253 CVE-2026-1225 (low, also SNYK-JAVA-CHQOSLOGBACK-15062482) External initialization of trusted variables or data stores vulnerability in Logback fix: Security scans now cover release artifacts only, where ktlint's logback is not present. ref: https://github.com/vulnlog/vulnlog/pull/253 SNYK-JAVA-CHQOSLOGBACK-17675439 (not affected) Expression injection vulnerability in Ktlints logback-core dependency. fix: Security scans now cover release artifacts only, where ktlint's logback is not present. ref: https://github.com/vulnlog/vulnlog/pull/253 SNYK-JAVA-CHQOSLOGBACK-17675449 (not affected) Deserialization of untrusted data vulnerability in `HardenedObjectInputStream` of `logback-core`. fix: Security scans now cover release artifacts only, where ktlint's logback is not present. ref: https://github.com/vulnlog/vulnlog/pull/253 SNYK-JAVA-CHQOSLOGBACK-17675450 (not affected) Deserialization of untrusted data vulnerability in `HardenedObjectInputStream` of `logback-classic`. fix: Security scans now cover release artifacts only, where ktlint's logback is not present. ref: https://github.com/vulnlog/vulnlog/pull/253 0.15.1 (2026-06-29) 7 fixed SNYK-JAVA-TOOLSJACKSONCORE-17434789 (not affected, also CVE-2026-54514) Server-side request forgery (SSRF) vulnerability in Jacksons `JDKFromStringDeserializer`. ref: https://github.com/vulnlog/vulnlog/pull/183 SNYK-JAVA-TOOLSJACKSONCORE-17440306 (not affected, also CVE-2026-54517) Incorrect authorization in Jackson's `BeanDeserializer._deserializeUsingPropertyBased` method. ref: https://github.com/vulnlog/vulnlog/pull/183 SNYK-JAVA-TOOLSJACKSONCORE-17440359 (not affected, also CVE-2026-54518) Incorrect authorization in jackson's `UnwrappedPropertyHandler.processUnwrappedCreatorProperties()` method. ref: https://github.com/vulnlog/vulnlog/pull/183 SNYK-JAVA-TOOLSJACKSONCORE-17440365 (not affected, also CVE-2026-54513) Incomplete list of disallowed inputs in Jacksons `BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray()` methods. ref: https://github.com/vulnlog/vulnlog/pull/183 SNYK-JAVA-TOOLSJACKSONCORE-17440597 (not affected, also CVE-2026-54512) Deserialization of untrusted data in Jacksons `DatabindContext._resolveAndValidateGeneric()` method. ref: https://github.com/vulnlog/vulnlog/pull/183 SNYK-JAVA-TOOLSJACKSONCORE-17457396 (not affected, also CVE-2026-54516) Improperly controlled modification of dynamically-determined object attributes in Jackson's `POJOPropertiesCollector._renameProperties()` and `BeanDeserializerFactory.addBeanProps()` methods. ref: https://github.com/vulnlog/vulnlog/pull/183 SNYK-JAVA-TOOLSJACKSONCORE-17457696 (not affected, also CVE-2026-54515) Improperly controlled modification of dynamically-determined object attributes in Jackson's `BeanDeserializerBase.createContextual()` method. ref: https://github.com/vulnlog/vulnlog/pull/183 0.12.0 (2026-04-19) 4 fixed: 3 low CVE-2020-29582 (low, also SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744) Information exposure vulnerability in Kotlin stdlib fix: Update ktlint to 14.2.0 also updates kotlin-stdlib to 2.1.0 CVE-2023-6378 (low, also SNYK-JAVA-CHQOSLOGBACK-6094942, SNYK-JAVA-CHQOSLOGBACK-6094943) Denial of service (DoS) vulnerability in logback fix: Update ktlint to 14.2.0 also updates logback to 1.3.14 CVE-2023-6481 (low, also SNYK-JAVA-CHQOSLOGBACK-6097492, SNYK-JAVA-CHQOSLOGBACK-6097493) Uncontrolled resource consumption (resource exhaustion) vulnerability in logback fix: Update ktlint to 14.2.0 also updates logback to 1.3.14 SNYK-JAVA-TOOLSJACKSONCORE-15907550 (not affected, also GHSA-2m67-wjpj-xhg9) Allocation of resources without limits or throttling vulnerability in Jackson ref: https://github.com/vulnlog/vulnlog/pull/82