<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>Clojure Q&amp;A - Recent questions tagged cve</title>
<link>https://ask.clojure.org/index.php/tag/cve</link>
<description></description>
<item>
<title>CVE-warning in org.fressian/fressian &lt;- org.clojure/data.fressian</title>
<link>https://ask.clojure.org/index.php/14872/cve-warning-org-fressian-fressian-org-clojure-data-fressian</link>
<description>&lt;p&gt;Dependency Information&lt;br&gt;
When running clj-watson in a project with     &lt;/p&gt;
&lt;p&gt;org.clojure/data.fressian {:mvn/version &quot;1.1.1&quot;}&lt;/p&gt;
&lt;p&gt;I get the following warning, refering to  &lt;a rel=&quot;nofollow&quot; href=&quot;https://nvd.nist.gov/vuln/detail/cve-2018-10054&quot;&gt;CVE-2018-10054&lt;/a&gt; (relates to a vulnerability in H2 and its usage in older versions of datomic). I assume this is a false positive.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;NAME: org.fressian/fressian&lt;br&gt;
VERSION: 0.6.8&lt;/p&gt;
&lt;p&gt;DEPENDENCY FOUND IN:&lt;/p&gt;
&lt;p&gt;[org.clojure/data.fressian]&lt;/p&gt;
&lt;p&gt;FIX SUGGESTION:&lt;/p&gt;
&lt;h3&gt;Vulnerabilities&lt;/h3&gt;
&lt;p&gt;SEVERITY: HIGH&lt;br&gt;
IDENTIFIERS: CVE-2018-10054&lt;br&gt;
CVSS: 8.8 (version 3.1)&lt;br&gt;
PATCHED VERSION: Information not available.&lt;/p&gt;
</description>
<category>Clojure</category>
<guid isPermaLink="true">https://ask.clojure.org/index.php/14872/cve-warning-org-fressian-fressian-org-clojure-data-fressian</guid>
<pubDate>Fri, 09 Jan 2026 12:45:21 +0000</pubDate>
</item>
</channel>
</rss>