Morningstar Liquibase Releases Free CVE Library for Enhanced Security Visibility
Article Content
- •Liquibase launched a free CVE Library on June 11, 2026, for community users.
- •The library provides visibility into known vulnerabilities for older Liquibase versions.
- •Automated scanning tools ensure continuous updates and security assessments.
On June 11, 2026, Liquibase launched the open-source Liquibase CVE Library, providing users with detailed security visibility into known vulnerabilities across releases, Docker images, binaries, and dependencies. This resource is designed for Liquibase Community users, especially those using older versions, to identify vulnerabilities and assess their security posture. The library allows users to view a high-level security grade, CVE counts, and compare vulnerabilities between different releases. Automated security scanning tools analyze each new release and previously published images for known vulnerabilities, maintaining an up-to-date view of the threat landscape. The Liquibase Community project has been downloaded over 100 million times, highlighting its widespread use. This initiative is part of Liquibase's broader commitment to transparency and security within the community.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…