This issue is opened for updating the CVE list for 26.0.0.10 to include the following. @ayoho @cluk fyi
|https://www.cve.org/CVERecord?id=CVE-2026-11713[CVE-2026-11713]
|5.4
|Information Disclosure
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:restConnector-2.0 feature
|https://www.cve.org/CVERecord?id=CVE-2026-14909[CVE-2026-14909]
|6.5
|SQL Injection
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:restConnector-2.0 feature
|https://www.cve.org/CVERecord?id=CVE-2026-49875[CVE-2026-49875]
|9.8
|Server-Side Request Forgery
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:jaxrs-2.0, feature:jaxrs-2.1, feature:jaxws-2.2, feature:xmlWS-3.0, feature:xmlWS-4.0, and feature:wsAtomicTransaction-1.2 features
|https://www.cve.org/CVERecord?id=CVE-2026-65432[CVE-2026-65432]
|7.5
|Cross-Site Scripting
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:jaxws-2.2, feature:xmlWS-3.0, feature:xmlWS-4.0, feature:wsSecurity-1.1, and feature:wsAtomicTransaction-1.2 features
|https://www.cve.org/CVERecord?id=CVE-2026-66142[CVE-2026-66142]
|7.5
|Denial of Service
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:jaxws-2.2, feature:xmlWS-3.0, and feature:xmlWS-4.0 features
|https://www.cve.org/CVERecord?id=CVE-2026-66143[CVE-2026-66143]
|7.5
|Denial of Service
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:jaxws-2.2, feature:xmlWS-3.0, and feature:xmlWS-4.0 features
|https://www.cve.org/CVERecord?id=CVE-2026-66144[CVE-2026-66144]
|7.5
|Denial of Service
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:jaxws-2.2, feature:xmlWS-3.0, and feature:xmlWS-4.0 features
|https://www.cve.org/CVERecord?id=CVE-2026-77816[CVE-2026-77816]
|6.5
|Path Traversal
|17.0.0.3-26.0.0.9
|26.0.0.10
|
|https://www.cve.org/CVERecord?id=CVE-2026-79715[CVE-2026-79715]
|5.5
|Path Traversal
|17.0.0.3-26.0.0.9
|26.0.0.10
|
This issue is opened for updating the CVE list for 26.0.0.10 to include the following. @ayoho @cluk fyi