diff --git a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md
index 66a970af7719..6293b69a53db 100644
--- a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md
+++ b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md
@@ -26,7 +26,7 @@ Improved Gradle SCM scanning is in Early Access. For more information, see [SCM
## Technical specifications
-Snyk supports Java analysis for Java versions up to SE 21 and is designed to process code from newer Java versions where feasible.
+Snyk supports Java analysis for Java versions up to SE 25 and is designed to process code from newer Java versions where feasible.
### Supported frameworks and libraries
@@ -38,6 +38,8 @@ For Java and Kotlin, the following frameworks and libraries are supported:
* Android Standard Library
* Apache Camel
* Apache Commons
+* Apache Commons Collections
+* Apache CXF
* Apache Tomcat
* Apache XML
* apache.mahou
@@ -50,7 +52,10 @@ For Java and Kotlin, the following frameworks and libraries are supported:
* Dropwizard
* elasticsearch
* FasterXML Jackson
+* Flyway
+* Google API Client
* Google Guava
+* Google OAuth Client
* grpc-java
* hibernate
* http4k
@@ -64,6 +69,7 @@ For Java and Kotlin, the following frameworks and libraries are supported:
* Java Standard Edition
* javalin
* Jax-RS
+* JAXB
* Jolokia
* jooq
{% endcolumn %}
@@ -72,6 +78,7 @@ For Java and Kotlin, the following frameworks and libraries are supported:
* Kyro
* Micronaut
* mongo-java-driver
+* MSAL4J
* Netty
* okhttp3
* org.apache.hc.client5
@@ -82,12 +89,14 @@ For Java and Kotlin, the following frameworks and libraries are supported:
* org.dom4j.io
* Playframework
* rxhttp
+* SAP Commerce (Hybris)
* Seam logger
* SnakeYaml
* Spongycastle
* Spring AI
* Spring boot
* Spring Cloud Config
+* Spring Security OAuth2 Client
* Spring Web, MVC and JDBC
* Spring WebFlux
* Struts
@@ -107,6 +116,8 @@ Kotlin only:
{% endcolumn %}
{% endcolumns %}
+For SAP Commerce (Hybris), Snyk Code analyzes FlexibleSearch queries for SQL injection. This is supported for Java only. Snyk Code recognizes values supplied through query parameter binding as safe and does not report them.
+
### Supported package managers and package registries
* Supported package managers: [Maven](https://maven.apache.org) and [Gradle](https://gradle.org), with the following supported versions:
diff --git a/discover-snyk/supported-languages/supported-languages-list/python/README.md b/discover-snyk/supported-languages/supported-languages-list/python/README.md
index 46bec0739718..31402e7e9481 100644
--- a/discover-snyk/supported-languages/supported-languages-list/python/README.md
+++ b/discover-snyk/supported-languages/supported-languages-list/python/README.md
@@ -57,6 +57,7 @@ For Python, the following frameworks and libraries are supported:
* huggingface\_hub
* iopg
* LangChain
+* LangChain LiteLLM
* ldap3
* libxml
* lxml
@@ -88,6 +89,8 @@ For Python, the following frameworks and libraries are supported:
{% endcolumn %}
{% endcolumns %}
+Snyk Code treats data returned through LangChain LiteLLM as untrusted, so it reports model output that reaches a sink the same way it reports any other untrusted input.
+
### Serverless support
Snyk Code analyzes Python functions that run on AWS Lambda. Snyk resolves handlers from AWS SAM and Serverless Framework configuration files, so it analyzes the function entry point as application code instead of skipping it.
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md
index 1baec6e12950..f082f11eac12 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md
@@ -16,7 +16,7 @@ Snyk Code is a developer-first static application security testing (SAST) soluti
The following table shows the Snyk Code features, including analysis, managing security issues in your code, and facilitating remediations within your development environment.
-
| Feature | Description |
|---|
| Issue filtering, sorting, and grouping | To identify the most common problems, you can filter issues based on their severity, programming language, priority score, and other criteria. See Filter existing Projects. |
| Priority Score | Sort by and prioritize the more important issues by incorporating factors such as issue prevalence, ease of fix, and risk factor into a single risk score. See Priority score. |
| Data flow | Visualize the path of the issue from source to sink with a step-by-step flow. See Data flow. |
| Vulnerability | Learn more about the vulnerability through curated content that explains how the vulnerability was created, what the risk factors are, and popular mitigation strategies for it. See Manage code vulnerabilities |
| Fix analysis | Gain insight and context by examining examples with links to actual code that fixes the same issues in similar data flows. See Breakdown of Code analysis. |
| Create Jira issue | Track and export Snyk issues to your Jira project. See Create a Jira issue. |
| Ignore issues | Configure Snyk to ignore suggested fixes for an issue to suppress specific warnings. For example, you may have deliberately used hard-coded passwords to test your routines in test code, or you are aware of an issue but have decided not to fix it. See Ignore issues. |
| Exclude files from the import process | Check for DeepCode/Snyk ignore files .gitignore .dcignore and read them if they exist. Using the information in these files, Snyk filters to identify only the files with the supported extensions in the Project directory and not above the current Project directory. Snyk Code bundles these files that are smaller than 4 MB and sends them to Snyk. ,gitignore exclusions are honored by the snyk code test CLI command. See also Exclude directories and files from the import process. |
| Interfile analysis | This is available for all languages supported by Snyk Code except Ruby. |
+| Feature | Description |
|---|
| Issue filtering, sorting, and grouping | To identify the most common problems, you can filter issues based on their severity, programming language, priority score, and other criteria. See Filter existing Projects. |
| Priority Score | Sort by and prioritize the more important issues by incorporating factors such as issue prevalence, ease of fix, and risk factor into a single risk score. See Priority score. |
| Data flow | Visualize the path of the issue from source to sink with a step-by-step flow. See Data flow. |
| Vulnerability | Learn more about the vulnerability through curated content that explains how the vulnerability was created, what the risk factors are, and popular mitigation strategies for it. See Manage code vulnerabilities |
| Fix analysis | Gain insight and context by examining examples with links to actual code that fixes the same issues in similar data flows. See Breakdown of Code analysis. |
| Create Jira issue | Track and export Snyk issues to your Jira project. See Create a Jira issue. |
| Ignore issues | Configure Snyk to ignore suggested fixes for an issue to suppress specific warnings. For example, you may have deliberately used hard-coded passwords to test your routines in test code, or you are aware of an issue but have decided not to fix it. See Ignore issues. |
| Exclude files from the import process | Check for DeepCode/Snyk ignore files .gitignore .dcignore and read them if they exist. Using the information in these files, Snyk filters to identify only the files with the supported extensions in the Project directory and not above the current Project directory. Snyk Code bundles these files that are smaller than 4 MB and sends them to Snyk. From September 14, 2026, .gitignore rules exclude only files that are untracked, matching the behavior of Git itself. Files committed to the repository are analyzed even when a .gitignore rule matches them. This applies to Snyk Code and Snyk Secrets across all interfaces and cannot be disabled. To get this behavior in CLI scans, upgrade to Snyk CLI 1.1307.0 or later. Use .snyk exclude patterns to deliberately exclude a path. See also Exclude directories and files from the import process. |
| Interfile analysis | This is available for all languages supported by Snyk Code except Ruby. |
## Deployment
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md
index ea55ba9ea6ec..a5c0c304dcf0 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md
@@ -14,17 +14,19 @@ Each rule includes the following information.
| Rule Name | CWEs | Security Categories |
| --------------------------------------------------- | ---------------- | ---------------------------------------------------------------------- |
| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
-| Use of Hardcoded Cryptographic Initialization Value | CWE-321 | OWASP:A04:2025 |
+| Use of Hardcoded Cryptographic Initialization Value | CWE-329 | OWASP:A04:2025 |
| No Dynamic SQL Clauses | CWE-89 | CWE Top 25, OWASP:A05:2025 |
| Inadequate Encryption Strength - Small Key Size | CWE-326 | OWASP:A04:2025 |
| Weak Cryptographic Primitive | CWE-327 | OWASP:A04:2025 |
-| Clear Text Logging | CWE-321 | OWASP:A04:2025 |
+| Clear Text Logging | CWE-312 | OWASP:A06:2025 |
| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
| Injection on Accept | CWE-20 | CWE Top 25, OWASP:A05:2025, OWASP-API:API10:2023, OWASP-Mobile:M4:2024 |
| Insecure Debug Features Enabled | CWE-489, CWE-215 | OWASP:A02:2025, OWASP:A10:2025 |
| Insecure Data Transmission | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
| SQL SELECT statement without WHERE clause | CWE-668 | OWASP:A01:2025 |
| Multiple CICS HANDLE ABEND Declarations | CWE-755 | OWASP:A10:2025 |
| Missing SQL Communication Area (SQLCA) | CWE-391 | OWASP:A10:2025 |
-| Ignored Error Condition | CWE-391 | OWASP:A10:2025 |
+| Ignored Error Condition | CWE-754 | OWASP:A10:2025 |
| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md
index c74a82b3be5a..ada898624dc4 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md
@@ -29,6 +29,7 @@ Each rule includes the following information.
| Android Fragment Injection | CWE-470 | OWASP:A05:2025 |
| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| HTTP Strict Transport Security (HSTS) Disabled | CWE-693 | OWASP:A06:2025 |
| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
| Disabled Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
| Inadequate Padding for AES encryption | CWE-326 | OWASP:A04:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md
index 7ac6571207b9..e72b45a7ed90 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md
@@ -24,6 +24,7 @@ Each rule includes the following information.
| Use of Hardcoded Cryptographic Initialization Value | CWE-329 | OWASP:A04:2025 |
| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
+| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
| Insecure default value | CWE-453 | None |
| Insecure File Permissions | CWE-732 | OWASP:A01:2025 |
@@ -47,6 +48,7 @@ Each rule includes the following information.
| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
| Arbitrary File Write via Archive Extraction (Tar Slip) | CWE-22 | CWE Top 25, OWASP:A01:2025 |
| Origin Validation Error | CWE-942, CWE-346 | OWASP:A02:2025, OWASP:A07:2025, OWASP-API:API8:2023 |
+| Improper Restriction of Rendered UI Layers or Frames | CWE-1021 | OWASP:A06:2025 |
| Cryptographic Issues | CWE-310 | None |
| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
| Python 2 source code | CWE-1104 | OWASP:A03:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md
index 7dc58d49d887..d49f28c49bc9 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md
@@ -21,6 +21,7 @@ Each rule includes the following information.
| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
+| HTTP Strict Transport Security (HSTS) Disabled | CWE-693 | OWASP:A06:2025 |
| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md
index f1e19bc7bdb3..3bde3e45581e 100644
--- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md
+++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md
@@ -32,3 +32,4 @@ Each rule includes the following information.
| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
+| XPath Injection | CWE-643 | OWASP:A05:2025 |