LIVE · cybersecurity feed
Live wire
cve record

CVE-2026-32735

Published
CVSS—
Severitynone
WeaknessCWE-20
ExploitedNot in CISA KEV

Description

openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting in version 5.1.1 and prior to version 5.5.1, the parent POM file of this project (`openapi-to-java-records-mustache-templates-parent`), which is used to centralize plugin configurations for multiple unit-test modules, uses `maven-dependency-plugin` to unpack arbitrary `.mustache` files from the `openapi-to-java-records-mustache-templates` artifact (of the same version). While this parent POM file is not intended for external use, it is published, and could be used by anyone, and does not follow the best security practices. The risk, is that if `openapi-to-java-records-mustac

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32735

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32735.