Object Computing maintains a focused set of infrastructure and framework products, with OpenDDS (a distributed data service), Micronaut (a JVM microservices framework), and Micronaut Security forming the core of its portfolio. Vulnerabilities affecting this vendor skew toward serious outcomes, concentrating in resource-management and configuration-control weakness classes such as uncontrolled resource consumption, amplification attacks, and external system configuration, which are characteristic of networked middleware and framework software that must handle untrusted input and dynamic load. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Objectcomputing over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7611CRITICAL All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating requ | Mar 30, 2020 | 9.8 | 31 | NO | NO |
CVE-2021-38445CRITICAL OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associated data, which may allow an attacker to remotely execute arbi | May 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-38429CRITICAL OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic, which may result in a denial-of | May 5, 2022 | 9.1 | 30 | NO | NO |
CVE-2026-33012HIGH Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through 4.10.16 used an unbounded Conc | Mar 20, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-33013HIGH Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not corre | Mar 20, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-67111HIGH An integer overflow in the RTPS protocol implementation of OpenDDS DDS before v3.33.0 allows attackers to cause a Denial of Service (DoS) via a crafted message. | Dec 23, 2025 | 7.5 | 24 | NO | NO |
CVE-2021-38447HIGH OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic, which may result in a denial-of | May 5, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-32769HIGH Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configura | Jul 16, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-23932HIGH OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenDDS applications that are exposed to untrusted RTPS network t | Feb 3, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-37915HIGH OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). OpenDDS crashes while parsing a malformed `PID_PROPERTY_LIST` in | Jul 21, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Objectcomputing.
Media articles that mention a CVE ID that affects a product developed by Objectcomputing — matched by CVE ID, not by vendor name.