{"id":"GHSA-9wxq-mwqw-8hhg","summary":"Jaspersoft Reports: Java Deserialization Vulnerability Lleads to Remote Code Execution (RCE)","details":"Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system","aliases":["CVE-2026-6009"],"modified":"2026-07-10T21:56:40.277022Z","published":"2026-05-19T18:32:14Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-10T21:42:57Z","nvd_published_at":"2026-05-19T18:16:29Z","cwe_ids":["CWE-502"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6009"},{"type":"WEB","url":"https://community.jaspersoft.com/advisories/jaspersoft-security-advisory-may-19-2026-jaspersoft-library-cve-2026-6009-r11"},{"type":"PACKAGE","url":"https://github.com/Jaspersoft/jasperreports"}],"affected":[{"package":{"name":"net.sf.jasperreports:jasperreports","ecosystem":"Maven","purl":"pkg:maven/net.sf.jasperreports/jasperreports"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.7"}]}],"versions":["3.6.0","3.6.1","3.6.2","3.7.0","3.7.1","3.7.2","3.7.3","3.7.4","3.7.5","3.7.6","4.0.0","4.0.1","4.0.2","4.1.1","4.1.2","4.1.3","4.5.0","4.5.1","4.6.0","4.7.0","4.7.1","4.8.0","5.0.0","5.0.1","5.0.4","5.1.0","5.1.2","5.2.0","5.5.0","5.5.1","5.5.2","5.6.0","5.6.1","6.0.0","6.0.2","6.0.3","6.0.4","6.1.0","6.1.1","6.10.0","6.11.0","6.12.0","6.12.1","6.12.2","6.13.0","6.14.0","6.15.0","6.16.0","6.17.0","6.18.0","6.18.1","6.19.0","6.19.1","6.2.0","6.2.1","6.2.2","6.20.0","6.20.1","6.20.2","6.20.3","6.20.4","6.20.5","6.20.6","6.21.0","6.21.2","6.21.3","6.21.4","6.21.5","6.3.0","6.3.1","6.4.0","6.4.1","6.4.3","6.5.0","6.5.1","6.6.0","6.7.0","6.7.1","6.8.0","6.8.1","6.9.0","7.0.0","7.0.1","7.0.2","7.0.3","7.0.4","7.0.5","7.0.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-9wxq-mwqw-8hhg/GHSA-9wxq-mwqw-8hhg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}