<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Kotlin (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/kotlin.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/kotlin-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Kotlin (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:06 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-31129 – Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31129</guid>
    <pubDate>Mon, 31 Mar 2025 19:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31129</strong></p>
  <p>Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnerability is fixed in 2.17.0 (2.x) and 3.7.0 (3.x).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24362 – In some circumstances, debug artifacts uploaded by the CodeQL Action after a fai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24362</guid>
    <pubDate>Fri, 24 Jan 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24362</strong></p>
  <p>In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may contain the environment variables from the workflow run, including any secrets that were exposed as environment variables to the workflow. Users with read access to the repository would be able to access this artifact, containing any secrets from the environment. This vulnerability i…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55875 – http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55875</guid>
    <pubDate>Thu, 12 Dec 2024 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55875</strong></p>
  <p>http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5.41.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive information on server, trigger Server-side Request Forgery and even execute code under some circumstances. Version 5.41.0.0 con…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29428 – In Gradle before version 7.0, on Unix-like systems, the system temporary directo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29428</guid>
    <pubDate>Tue, 13 Apr 2021 20:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29428</strong></p>
  <p>In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation from an attacker quickly deleting and recreating files in the system temporary directory. This vulnerability impacted builds using precompiled script…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-378</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15824 – In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15824</guid>
    <pubDate>Sat, 08 Aug 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15824</strong></p>
  <p>In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-16303 – A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16303</guid>
    <pubDate>Sat, 14 Sep 2019 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-16303</strong></p>
  <p>A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This allows an attacker (if able to obtain their own password reset URL) to compute the value for all other password resets for other accounts, thus allowing privilege escalation or account takeover.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10103 – JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10103</guid>
    <pubDate>Wed, 03 Jul 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10103</strong></p>
  <p>JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10102 – JetBrains Ktor framework (created using the Kotlin IDE template) versions before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10102</guid>
    <pubDate>Wed, 03 Jul 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10102</strong></p>
  <p>JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10101 – JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10101</guid>
    <pubDate>Wed, 03 Jul 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10101</strong></p>
  <p>JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10101">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
