Skip to content

[FP]: CVE-2026-2587, CVE-2026-2586 and CVE-2024-9329 in rngom-4.0.9.jar #8612

Description

@ZarkonPro

Package URl

pkg:maven/com.sun.xml.bind.external/rngom@4.0.9

CPE

cpe:2.3:a:eclipse:glassfish:4.0.9:::::::*

CVE

CVE-2026-2587

ODC Integration

{"label" => "Maven Plugin"}

ODC Version

12.2.2

Description

Hi.

From org.glassfish.jaxb.jaxb-runtime@4.0.9 (last library version), it uses com.sun.xml.bind.external/rngom@4.0.9 (last library version too) and dependency check reports CVE-2026-2587, CVE-2026-2586 and CVE-2024-9329

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions