org.yamcs:yamcs-core
Maven16 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.yamcs:yamcs-corepage 1 of 1
- CVE-2026-42568MEDIUMCVSS 4.3EG 4.3fixed in 5.12.72026-05-26
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the…
- CVE-2026-44595MEDIUMCVSS 4.3EG 4.3fixed in 5.12.72026-05-27
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/…
- CVE-2026-44596CRITICALCVSS 9.8EG 9.8fixed in 5.12.72026-05-27
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or fail…
- CVE-2026-44632CRITICALCVSS 9.1EG 9.1fixed in 5.12.72026-05-27
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evalu…
- CVE-2026-46562CRITICALCVSS 9.8EG 9.8fixed in 5.12.72026-05-27
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed w…
- CVE-2026-46621CRITICALCVSS 9.1EG 9.1fixed in 5.12.72026-05-27
vulnerable: 0.29.3 ... 5.9.9 (165 versions)
Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enf…
- CVE-2026-55511CRITICALCVSS 9.1EG 9.1fixed in 5.13.2 or 5.12.8, by version range2026-08-28
vulnerable: 0.29.3 ... 5.9.9 (166 versions)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillC…
- CVE-2026-55521HIGHCVSS 8.8EG 8.8fixed in 5.13.2 or 5.12.8, by version range2026-08-28
vulnerable: 0.29.3 ... 5.9.9 (166 versions)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and Tim…
- CVE-2026-55545MEDIUMCVSS 6.5EG 6.5fixed in 5.12.8 or 5.13.2, by version range2026-08-28
vulnerable: 5.13.0, 5.13.1
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic w…
- CVE-2026-55547MEDIUMCVSS 4.3EG 4.3fixed in 5.13.2 or 5.12.8, by version range2026-08-28
vulnerable: 0.29.3 ... 5.9.9 (166 versions)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java.…
- CVE-2026-55548MEDIUMCVSS 4.3EG 4.3fixed in 5.13.2 or 5.12.8, by version range2026-07-16
vulnerable: 0.29.3 ... 5.9.9 (166 versions)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omit…
- CVE-2026-55549MEDIUMCVSS 6.5EG 6.5fixed in 5.9.42026-08-28
vulnerable: 0.29.3 ... 5.9.3 (121 versions)
Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize.html without adequate HTML escaping by …
- CVE-2026-55552HIGHCVSS 7.5EG 7.5fixed in 5.12.02026-08-28
vulnerable: 0.29.3 ... 5.9.9 (158 versions)
Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the c…
- CVE-2026-55559CRITICALCVSS 9.8EG 9.8fixed in 5.13.2 or 5.12.8, by version range2026-08-28
vulnerable: 0.29.3 ... 5.9.9 (166 versions)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templatin…
- CVE-2026-55565CRITICALCVSS 9.9EG 9.9fixed in 5.13.2 or 5.12.8, by version range2026-08-28
vulnerable: 0.29.3 ... 5.9.9 (166 versions)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source com…
- CVE-2026-55566MEDIUMCVSS 4.3EG 4.3fixed in 5.13.2 or 5.12.8, by version range2026-08-28
vulnerable: 0.29.3 ... 5.9.9 (166 versions)
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component.t…
Check whether org.yamcs:yamcs-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.yamcs:yamcs-core CVEs against the assets you own.
Book a Demo →