CVE-2024-22949: Jfree Jfreechart

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnnotation. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

Affected products

  • Jfree Jfreechart: version 1.5.4 only

Published 2024-04-08. Last modified 2026-07-09.