Known vulnerabilities in JGit

Vendor: Eclipse
Software: JGit
Software CPE: cpe:2.3:a:eclipse:jgit:*:*:*:*:*:*:*:*
Total vulnerabilities: 2
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting JGit JGit is affected by 2 known vulnerabilities: 1 high, 1 medium Critical High Medium Low

Vulnerabilities (2)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU114059 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2025-4949
CWE-611 High
No
No
7.2.1.202505142326-r 14.08.2025 SB2025081408
SB2025081409
SB2025081410
and 21 more
#VU81948 - Improper Link Resolution Before File Access ('Link Following')
CVE-2023-4759
CWE-59 Medium
No
No
6.6.1.202309021850-r 12.10.2023 SB2023101242
SB2023101243
SB2023103012
and 21 more