| Package | Vulnerability | Severity | Version | Fix Available | CVSS |
|---|---|---|---|---|---|
| ch.qos.logback:logback-core | CVE-2026-10532 | LOW | 1.5.25 | true | N/A |
| ch.qos.logback:logback-core | CVE-2026-9828 | LOW | 1.5.25 | true | N/A |
| org.apache.httpcomponents.client5:httpclient5 | CVE-2026-64607 | MEDIUM | 5.5.2 | true | 5.3 |
| org.apache.httpcomponents.core5:httpcore5 | CVE-2026-54399 | HIGH | 5.3.6 | true | 7.5 |
| org.apache.httpcomponents.core5:httpcore5-h2 | CVE-2026-54428 | HIGH | 5.3.6 | true | 7.5 |
| org.apache.logging.log4j:log4j-api | CVE-2026-49844 | MEDIUM | 2.24.3 | true | 5.9 |
| CRITICAL: 0 | HIGH: 2 | MEDIUM: 2 | LOW: 2 | UNKNOWN: 0 | Total: 6 |