Jodd is a lightweight Java framework and utility library that provides HTTP connectivity and serialization tooling; vulnerabilities affecting it cluster around deserialization of untrusted data and injection-class weaknesses in data processing and output handling. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jodd over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-21234CRITICAL Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set. | May 21, 2020 | 9.8 | 34 | NO | NO |
CVE-2022-29631HIGH Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabiliti | Jun 6, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jodd.
Media articles that mention a CVE ID that affects a product developed by Jodd — matched by CVE ID, not by vendor name.