Glassfish
Vendor:
First CVE: Jan 27, 2023 · Active for 3 years
12
Total CVEs
More Total CVEs than 90% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Glassfish over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 27, 2023
3 years ago
Most Recent CVE
May 19, 2026
66 days ago
CVE Severity & Scoring
Glassfish12 CVEs
50%
8%
42%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (41.7%)
Unknown0 (0.0%)
Required7 (58.3%)
Privileges Required
Low2 (16.7%)
High1 (8.3%)
None9 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2587CRITICAL A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes | May 19, 2026 | 9.6 | 40 | NO | NO |
CVE-2026-2586CRITICAL An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allo | May 19, 2026 | 9.1 | 38 | NO | NO |
CVE-2024-9408CRITICAL In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints. | Jul 16, 2025 | 9.8 | 29 | NO | NO |
CVE-2024-9342CRITICAL In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 add | Jul 16, 2025 | 9.8 | 26 | NO | NO |
CVE-2022-2712HIGH In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitatio | Jan 27, 2023 | 7.5 | 26 | NO | NO |
CVE-2023-5763CRITICAL In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to | Nov 3, 2023 | 9.8 | 24 | NO | NO |
CVE-2024-9343MEDIUM In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting
attacks in the Administration Console. | Jul 16, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-10029MEDIUM In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting
attacks in the Administration Console. | Jul 16, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-9329MEDIUM In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/d | Sep 30, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-8646MEDIUM In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed.
This vulnerability is caused by the vulnerability (CVE-2023-41080) in the | Sep 11, 2024 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Glassfish
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0.16 | 1 | 9.8 | 0.4% | 0 | 0 |
| 7.0.15 | 4 | 5.8 | 0.2% | 0 | 0 |
| 6.2.5 | 1 | 9.8 | 0.3% | 0 | 0 |