chiprook
← Security
SecurityOctober 9, 2026, 23:07

Lightwell finds 400+ vulnerabilities in Java libraries

Lightwell, the open-source security initiative by IBM and Red Hat, has identified more than 400 previously undiscovered vulnerabilities in widely used Java libraries, including a critical sandbox bypass in Thymeleaf with a CVSS score of 9.1. The companies opened the Lightwell Clearinghouse service for customers to submit their code dependencies and plan to backport fixes into production apps.

Lightwell finds 400+ vulnerabilities in Java libraries
#IBM#RedHat#Lightwell#Thymeleaf
Read next
Security

IBM and Red Hat patch 400-plus unknown Java flaws, open Clearinghouse

Security

Red Hat Opens Lightwell Clearinghouse Premier to All Enterprises

Security

Athena coalition discloses first 14 'silent' Java vulnerabilities

Security

IBM: AI worsens open source vulnerability flood, but can also help