Maven · repo1.maven.org
com.vaadin:vaadin-cdi
Java Jndi Lookup: JNDI / Naming.lookup — remote class-loading primitive (Log4Shell family).
Why PkgRadar flagged 16.1.0-beta1
| Severity | Signal | Evidence |
|---|---|---|
| medium | Java Jndi Lookup | JNDI / Naming.lookup — remote class-loading primitive (Log4Shell family). · com/vaadin/cdi/util/BeanManagerProvider.java |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
16.1.0-beta1 | Review | 25 | 2026-06-12 |
Block this in CI
pkgradar gate --ecosystem maven com.vaadin:[email protected]