-

Liquibase Launches Free CVE Library for Community Users

New public resource gives Liquibase Community users release-by-release security visibility into known vulnerabilities across releases, Docker images, binaries, and dependencies.

AUSTIN, Texas--(BUSINESS WIRE)--Today, Liquibase is proud to release the open source Liquibase CVE Library (Common Vulnerabilities and Exposures Library) to foster security and transparency across the Liquibase Community. The free, publicly available library helps users of older versions of Liquibase Community identify existing vulnerabilities and get a clearer sense of their security posture. By tying vulnerability data directly to Liquibase releases, the CVE Library helps teams see their risk exposure, compare versions, and take informed action to secure the software they run.

The CVE Library lets users see a high-level security grade and CVE counts for the latest release, drill into any specific version for the full vulnerability list, or use the comparison tool to see which CVEs were resolved or introduced between two releases

Share

Attackers need only to find a single exploit to breach a network and IT infrastructure, making comprehensive CVE libraries increasingly invaluable to security teams seeking to stay ahead of Mythos-class threat capabilities by patching all known weaknesses before they can be targeted.

To date, the Liquibase Community project has been downloaded over 100 million times.

How does the Liquibase CVE Library work?

Every time Liquibase ships a new release, automated security scanning tools analyze both the Docker image and the Liquibase binary for known vulnerabilities. Scanning also runs against previously published images, maintaining an up-to-date view of the evolving threat landscape and catching anything that surfaces post-release. The site organizes everything by image and version. You can see a high-level security grade and CVE counts for the latest release, drill into any specific version for the full vulnerability list, or use the comparison tool to see exactly which CVEs were resolved, or introduced, between two releases.

Which environments are supported?

The CVE Library currently covers two areas:

  • Docker images: The official Liquibase Community Docker image.
  • Liquibase binary: Vulnerabilities in the Liquibase JARs themselves, regardless of how you install it.

What you'll see

For each vulnerability, the CVE Library shows:

  • CVE ID, Severity, and CVSS score: Presented with clear information and links to learn more.
  • Affected package: The specific details needed to understand what is vulnerable.
  • Fix available: The package version that resolves it, if one exists; and where applicable, the first Liquibase image version where the CVE no longer appears.
  • Component type: Additional vulnerability details to help understand the risk.
  • First-party vs. third-party: Whether the vulnerability is in Liquibase's own code or an upstream dependency.

The full list is filterable by severity, component type, and keyword search, and can be exported as CSV or PDF. (See figures.)

Part of a broader commitment to the Community

The CVE Library doesn't stand alone. Since September of 2025, Liquibase has released a steady stream of enhancements and fixes for the Liquibase Community. Recently, in May of 2026, Liquibase standardized on two clear paths to updates: quarterly Community releases and continuous nightly builds on GitHub (available at github.com/liquibase/liquibase/releases/tag/nightly). The CVE Library now makes that ongoing work readily visible so users don't have to just trust that issues are being addressed, they can see it, release by release.

For teams that need enterprise assurance

The Liquibase CVE Library gives Community users clear visibility into known vulnerability exposure. For organizations running Liquibase in regulated, mission-critical, AI-enabled, or enterprise production environments, visibility is often the first step. Liquibase Secure provides a fully supported enterprise distribution with SLA-backed support, tested components, policy checks, drift detection, structured audit logs, and governance controls for teams that need to reduce risk while maintaining delivery velocity.

Take a look and get involved

The Liquibase Community thrives because people around the world step up to contribute. Here's how to get in touch and take part:

About Liquibase

Liquibase empowers teams to deliver mission-critical applications, data products, and AI initiatives by automating and governing database change. We are the company behind Liquibase Community, a project with deep open-source roots that has been downloaded more than 100 million times and is trusted by thousands of teams worldwide.

Liquibase Secure, built on that proven community foundation, is the only enterprise platform that unifies DevOps, security, and compliance at the database layer. It enables organizations to deliver applications and data products with velocity, safety, and confidence. Trusted by the world’s most innovative and highly regulated enterprises, Liquibase Secure powers the last mile of application and data delivery.

Learn more at www.liquibase.com. Follow us on LinkedIn and X.

Contacts

Media Contact:
Torry Cullen
Torry@MadisonAlexanderPR.com
(781) 363-2542

Liquibase


Release Versions

Contacts

Media Contact:
Torry Cullen
Torry@MadisonAlexanderPR.com
(781) 363-2542

More News From Liquibase

Liquibase Introduces Agent Safe Governance for AI-Generated Database Change

AUSTIN, Texas--(BUSINESS WIRE)--Liquibase, the leader in database change governance, today announced Liquibase Secure 5.2, a major release introducing Agent Safe Governance for AI-generated database change. Liquibase Secure 5.2 helps enterprises validate, track, and govern database change before and after production, whether created by humans or AI. Liquibase also announced that Liquibase Secure earned five 2026 TrustRadius Top Rated Awards across Database DevOps, Build Automation, Release Mana...

Liquibase Financial Services Playbook Offers New Findings, Best Practices to Let FinServs Protect Data and Navigate the Mythos-Class Threat Age

AUSTIN, Texas--(BUSINESS WIRE)--Liquibase, provider of database change governance solutions used by many of the world’s leading financial services organizations, today announced The Financial Services Playbook for Governed Database Change, a new executive guide designed to help financial institutions modernize and secure one of the last major control gaps in enterprise technology delivery: database change. Built for CIOs, CTOs, platform engineering leaders, database architects, and compliance t...

Liquibase Unveils Change Intelligence and New Connectors for Governed Database Delivery

AUSTIN, Texas--(BUSINESS WIRE)--Liquibase, the leader in Database Change Governance, today unveiled Liquibase Change Intelligence and a new suite of Liquibase Secure Deployment Connectors, expanding how enterprises understand, govern, and operationalize database change across modern delivery environments. The new capabilities are designed to help teams understand database changes, monitor delivery performance, identify risk earlier, resolve issues up to 95% faster, and centralize audit evidence...
Back to Newsroom