Clojure is a functional programming language and runtime that operates within the JVM ecosystem, presenting a narrow but notable product surface centered on the language implementation itself. The durable signal in its vulnerability profile centers on deserialization of untrusted data, a structural risk inherent to JVM-based runtimes and language features that accept serialized objects. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clojure over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-20189CRITICAL In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted | Jan 22, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-22871HIGH An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function. | Feb 29, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clojure.
Media articles that mention a CVE ID that affects a product developed by Clojure — matched by CVE ID, not by vendor name.