Vulnerable Library - spring-boot-starter-web-4.0.4.jar
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Dependency |
Type |
Fixed in (spring-boot-starter-web version) |
Remediation Possible** |
| CVE-2026-43512 |
Critical |
9.8 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-41293 |
Critical |
9.8 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-59084 |
Critical |
9.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-59083 |
Critical |
9.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-43515 |
Critical |
9.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-40976 |
Critical |
9.1 |
spring-boot-4.0.4.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-29145 |
Critical |
9.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-54513 |
High |
8.1 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-54512 |
High |
8.1 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| WS-2026-0010 |
High |
7.5 |
jackson-core-3.1.0.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-68494 |
High |
7.5 |
jackson-core-3.1.0.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-43513 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-41850 |
High |
7.5 |
spring-expression-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41842 |
High |
7.5 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41284 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-34487 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-34483 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-29146 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-29129 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-24880 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-42498 |
High |
7.3 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-41845 |
High |
7.1 |
detected in multiple dependencies |
Transitive |
N/A* |
❌ |
| CVE-2026-40973 |
High |
7.0 |
spring-boot-4.0.4.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-59889 |
Medium |
6.5 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-59888 |
Medium |
6.5 |
jackson-databind-3.1.0.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-54518 |
Medium |
6.5 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-22740 |
Medium |
6.5 |
spring-web-7.0.6.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-25854 |
Medium |
6.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-41846 |
Medium |
5.9 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41843 |
Medium |
5.9 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41841 |
Medium |
5.9 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41840 |
Medium |
5.9 |
spring-web-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-54517 |
Medium |
5.3 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-54516 |
Medium |
5.3 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-54515 |
Medium |
5.3 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-54514 |
Medium |
5.3 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-41853 |
Medium |
5.3 |
detected in multiple dependencies |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41851 |
Medium |
5.3 |
spring-expression-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-32990 |
Medium |
5.3 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-22745 |
Medium |
5.3 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-40975 |
Medium |
4.8 |
spring-boot-4.0.4.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-40977 |
Medium |
4.7 |
spring-boot-4.0.4.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-41854 |
Medium |
4.2 |
spring-web-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41844 |
Medium |
4.2 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41839 |
Medium |
4.2 |
spring-web-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-43514 |
Low |
3.7 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-41852 |
Low |
3.7 |
spring-expression-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41848 |
Low |
3.7 |
spring-core-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-22741 |
Low |
3.1 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.6 |
❌ |
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Partial details (17 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.
CVE-2026-43512
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0.
Older unsupported versions any also be affect
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Publish Date: 2026-05-12
URL: CVE-2026-43512
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat:tomcat-catalina:11.0.22,org.apache.tomcat:tomcat-catalina:9.0.118,org.apache.tomcat:tomcat-catalina:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,https://github.com/apache/tomcat.git - 9.0.118
Step up your Open Source Security Game with Mend here
CVE-2026-41293
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Improper Input Validation vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27.
Older, end of support versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Publish Date: 2026-05-12
URL: CVE-2026-41293
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat:tomcat-coyote:9.0.118,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-coyote:11.0.22,org.apache.tomcat:tomcat-coyote:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 9.0.118,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118
Step up your Open Source Security Game with Mend here
CVE-2026-59084
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
Publish Date: 2026-07-14
URL: CVE-2026-59084
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7
Release Date: 2026-07-14
Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:11.0.24,org.apache.tomcat:tomcat-catalina:10.1.57,org.apache.tomcat.embed:tomcat-embed-core:9.0.120,org.apache.tomcat.embed:tomcat-embed-core:10.1.57,org.apache.tomcat:tomcat-catalina:9.0.120,org.apache.tomcat:tomcat-catalina:11.0.24
Step up your Open Source Security Game with Mend here
CVE-2026-59083
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
Publish Date: 2026-07-14
URL: CVE-2026-59083
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-07-14
Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.120,https://github.com/apache/tomcat.git - 9.0.120,org.apache.tomcat:tomcat-catalina:11.0.24,org.apache.tomcat.embed:tomcat-embed-core:9.0.120,https://github.com/apache/tomcat.git - 11.0.24,org.apache.tomcat.embed:tomcat-embed-core:11.0.24,org.apache.tomcat:tomcat-catalina:10.1.57,https://github.com/apache/tomcat.git - 10.1.57,org.apache.tomcat.embed:tomcat-embed-core:10.1.57
Step up your Open Source Security Game with Mend here
CVE-2026-43515
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Publish Date: 2026-05-12
URL: CVE-2026-43515
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat:tomcat-catalina:11.0.22,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-catalina:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,org.apache.tomcat:tomcat-catalina:9.0.118,https://github.com/apache/tomcat.git - 9.0.118
Step up your Open Source Security Game with Mend here
CVE-2026-40976
Vulnerable Library - spring-boot-4.0.4.jar
Spring Boot
Library home page: https://spring.io/projects/spring-boot
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework.boot/spring-boot/4.0.4/93d6e7c5b747d640bbad17971c5ce957bee88c5f/spring-boot-4.0.4.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- spring-boot-web-server-4.0.4.jar
- ❌ spring-boot-4.0.4.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
Publish Date: 2026-04-27
URL: CVE-2026-40976
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-04-27
Fix Resolution: org.springframework.boot:spring-boot-security:4.0.6,https://github.com/spring-projects/spring-boot.git - v4.0.6
Step up your Open Source Security Game with Mend here
CVE-2026-29145
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13.
Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
Publish Date: 2026-04-09
URL: CVE-2026-29145
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-04-09
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.20
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.5
Step up your Open Source Security Game with Mend here
CVE-2026-54513
Vulnerable Library - jackson-databind-3.1.0.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: https://github.com/FasterXML/jackson
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-databind/3.1.0/59a342020cc4f5a49335c16820be6ed8ca8ee6c7/jackson-databind-3.1.0.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-jackson-4.0.4.jar
- spring-boot-jackson-4.0.4.jar
- ❌ jackson-databind-3.1.0.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Publish Date: 2026-06-23
URL: CVE-2026-54513
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-06-23
Fix Resolution: https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4
Step up your Open Source Security Game with Mend here
CVE-2026-54512
Vulnerable Library - jackson-databind-3.1.0.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: https://github.com/FasterXML/jackson
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-databind/3.1.0/59a342020cc4f5a49335c16820be6ed8ca8ee6c7/jackson-databind-3.1.0.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-jackson-4.0.4.jar
- spring-boot-jackson-4.0.4.jar
- ❌ jackson-databind-3.1.0.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Publish Date: 2026-06-23
URL: CVE-2026-54512
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-06-23
Fix Resolution: https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.8
Step up your Open Source Security Game with Mend here
WS-2026-0010
Vulnerable Library - jackson-core-3.1.0.jar
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
Library home page: https://github.com/FasterXML/jackson-core
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-core/3.1.0/df0dc5d0bf720739ae7b6afeee2af2aabf88905b/jackson-core-3.1.0.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-jackson-4.0.4.jar
- spring-boot-jackson-4.0.4.jar
- jackson-databind-3.1.0.jar
- ❌ jackson-core-3.1.0.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Jackson Core 3.x does not consistently enforce StreamReadConstraints.maxDocumentLength. Oversized JSON documents can be accepted without a StreamConstraintsException across blocking, async, and DataInput parser entry points, allowing configured document-length limits to be bypassed and weakening denial-of-service protections.
Publish Date: 2026-04-01
URL: WS-2026-0010
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-04-01
Fix Resolution (tools.jackson.core:jackson-core): 3.1.1
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.6
Step up your Open Source Security Game with Mend here
CVE-2026-68494
Vulnerable Library - jackson-core-3.1.0.jar
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
Library home page: https://github.com/FasterXML/jackson-core
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-core/3.1.0/df0dc5d0bf720739ae7b6afeee2af2aabf88905b/jackson-core-3.1.0.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-jackson-4.0.4.jar
- spring-boot-jackson-4.0.4.jar
- jackson-databind-3.1.0.jar
- ❌ jackson-core-3.1.0.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.
The earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.
As a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.
The equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.
Impact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.
Exploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.
This issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08).
Publish Date: 2026-08-04
URL: CVE-2026-68494
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-04
Fix Resolution (tools.jackson.core:jackson-core): 3.1.4
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.7
Step up your Open Source Security Game with Mend here
CVE-2026-43513
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Publish Date: 2026-05-12
URL: CVE-2026-43513
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.118,https://github.com/apache/tomcat.git - 10.1.55,org.apache.tomcat:tomcat-catalina:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,https://github.com/apache/tomcat.git - 9.0.118,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,org.apache.tomcat:tomcat-catalina:11.0.22
Step up your Open Source Security Game with Mend here
CVE-2026-41850
Vulnerable Library - spring-expression-7.0.6.jar
Spring Expression Language (SpEL)
Library home page: https://github.com/spring-projects/spring-framework
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-expression/7.0.6/c00c73c545c81e2eae224a46a7c509fca74a2860/spring-expression-7.0.6.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-webmvc-4.0.4.jar
- spring-webmvc-7.0.6.jar
- ❌ spring-expression-7.0.6.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Publish Date: 2026-06-09
URL: CVE-2026-41850
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://spring.io/security/cve-2026-41850
Release Date: 2026-06-09
Fix Resolution (org.springframework:spring-expression): 7.0.8
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.7
Step up your Open Source Security Game with Mend here
CVE-2026-41842
Vulnerable Library - spring-webmvc-7.0.6.jar
Spring Web MVC
Library home page: https://github.com/spring-projects/spring-framework
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-webmvc-4.0.4.jar
- ❌ spring-webmvc-7.0.6.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.Affected versions:Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Publish Date: 2026-06-09
URL: CVE-2026-41842
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://spring.io/security/cve-2026-41842
Release Date: 2026-06-09
Fix Resolution (org.springframework:spring-webmvc): 7.0.8
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.7
Step up your Open Source Security Game with Mend here
CVE-2026-41284
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117.
Older, unsupported versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Publish Date: 2026-05-12
URL: CVE-2026-41284
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,https://github.com/apache/tomcat.git - 9.0.118,org.apache.tomcat.embed:tomcat-embed-core:9.0.118
Step up your Open Source Security Game with Mend here
CVE-2026-34487
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Publish Date: 2026-04-09
URL: CVE-2026-34487
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-04-09
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.21
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.6
Step up your Open Source Security Game with Mend here
CVE-2026-34483
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
Publish Date: 2026-04-09
URL: CVE-2026-34483
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-04-09
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.21
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.6
Step up your Open Source Security Game with Mend here
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0.
Older unsupported versions any also be affect
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Publish Date: 2026-05-12
URL: CVE-2026-43512
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat:tomcat-catalina:11.0.22,org.apache.tomcat:tomcat-catalina:9.0.118,org.apache.tomcat:tomcat-catalina:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,https://github.com/apache/tomcat.git - 9.0.118
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Improper Input Validation vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27.
Older, end of support versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Publish Date: 2026-05-12
URL: CVE-2026-41293
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat:tomcat-coyote:9.0.118,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-coyote:11.0.22,org.apache.tomcat:tomcat-coyote:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 9.0.118,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
Publish Date: 2026-07-14
URL: CVE-2026-59084
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7
Release Date: 2026-07-14
Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:11.0.24,org.apache.tomcat:tomcat-catalina:10.1.57,org.apache.tomcat.embed:tomcat-embed-core:9.0.120,org.apache.tomcat.embed:tomcat-embed-core:10.1.57,org.apache.tomcat:tomcat-catalina:9.0.120,org.apache.tomcat:tomcat-catalina:11.0.24
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
Publish Date: 2026-07-14
URL: CVE-2026-59083
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-07-14
Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.120,https://github.com/apache/tomcat.git - 9.0.120,org.apache.tomcat:tomcat-catalina:11.0.24,org.apache.tomcat.embed:tomcat-embed-core:9.0.120,https://github.com/apache/tomcat.git - 11.0.24,org.apache.tomcat.embed:tomcat-embed-core:11.0.24,org.apache.tomcat:tomcat-catalina:10.1.57,https://github.com/apache/tomcat.git - 10.1.57,org.apache.tomcat.embed:tomcat-embed-core:10.1.57
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Publish Date: 2026-05-12
URL: CVE-2026-43515
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat:tomcat-catalina:11.0.22,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-catalina:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,org.apache.tomcat:tomcat-catalina:9.0.118,https://github.com/apache/tomcat.git - 9.0.118
Step up your Open Source Security Game with Mend here
Vulnerable Library - spring-boot-4.0.4.jar
Spring Boot
Library home page: https://spring.io/projects/spring-boot
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework.boot/spring-boot/4.0.4/93d6e7c5b747d640bbad17971c5ce957bee88c5f/spring-boot-4.0.4.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
Publish Date: 2026-04-27
URL: CVE-2026-40976
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-04-27
Fix Resolution: org.springframework.boot:spring-boot-security:4.0.6,https://github.com/spring-projects/spring-boot.git - v4.0.6
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13.
Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
Publish Date: 2026-04-09
URL: CVE-2026-29145
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-04-09
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.20
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.5
Step up your Open Source Security Game with Mend here
Vulnerable Library - jackson-databind-3.1.0.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: https://github.com/FasterXML/jackson
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-databind/3.1.0/59a342020cc4f5a49335c16820be6ed8ca8ee6c7/jackson-databind-3.1.0.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Publish Date: 2026-06-23
URL: CVE-2026-54513
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-06-23
Fix Resolution: https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4
Step up your Open Source Security Game with Mend here
Vulnerable Library - jackson-databind-3.1.0.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: https://github.com/FasterXML/jackson
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-databind/3.1.0/59a342020cc4f5a49335c16820be6ed8ca8ee6c7/jackson-databind-3.1.0.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Publish Date: 2026-06-23
URL: CVE-2026-54512
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-06-23
Fix Resolution: https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.8
Step up your Open Source Security Game with Mend here
Vulnerable Library - jackson-core-3.1.0.jar
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
Library home page: https://github.com/FasterXML/jackson-core
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-core/3.1.0/df0dc5d0bf720739ae7b6afeee2af2aabf88905b/jackson-core-3.1.0.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Jackson Core 3.x does not consistently enforce StreamReadConstraints.maxDocumentLength. Oversized JSON documents can be accepted without a StreamConstraintsException across blocking, async, and DataInput parser entry points, allowing configured document-length limits to be bypassed and weakening denial-of-service protections.
Publish Date: 2026-04-01
URL: WS-2026-0010
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-04-01
Fix Resolution (tools.jackson.core:jackson-core): 3.1.1
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.6
Step up your Open Source Security Game with Mend here
Vulnerable Library - jackson-core-3.1.0.jar
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
Library home page: https://github.com/FasterXML/jackson-core
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-core/3.1.0/df0dc5d0bf720739ae7b6afeee2af2aabf88905b/jackson-core-3.1.0.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.
The earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.
As a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.
The equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.
Impact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.
Exploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.
This issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08).
Publish Date: 2026-08-04
URL: CVE-2026-68494
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-04
Fix Resolution (tools.jackson.core:jackson-core): 3.1.4
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.7
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Publish Date: 2026-05-12
URL: CVE-2026-43513
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.118,https://github.com/apache/tomcat.git - 10.1.55,org.apache.tomcat:tomcat-catalina:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,https://github.com/apache/tomcat.git - 9.0.118,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,org.apache.tomcat:tomcat-catalina:11.0.22
Step up your Open Source Security Game with Mend here
Vulnerable Library - spring-expression-7.0.6.jar
Spring Expression Language (SpEL)
Library home page: https://github.com/spring-projects/spring-framework
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-expression/7.0.6/c00c73c545c81e2eae224a46a7c509fca74a2860/spring-expression-7.0.6.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Publish Date: 2026-06-09
URL: CVE-2026-41850
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://spring.io/security/cve-2026-41850
Release Date: 2026-06-09
Fix Resolution (org.springframework:spring-expression): 7.0.8
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.7
Step up your Open Source Security Game with Mend here
Vulnerable Library - spring-webmvc-7.0.6.jar
Spring Web MVC
Library home page: https://github.com/spring-projects/spring-framework
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.Affected versions:Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Publish Date: 2026-06-09
URL: CVE-2026-41842
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://spring.io/security/cve-2026-41842
Release Date: 2026-06-09
Fix Resolution (org.springframework:spring-webmvc): 7.0.8
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.7
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117.
Older, unsupported versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Publish Date: 2026-05-12
URL: CVE-2026-41284
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,https://github.com/apache/tomcat.git - 9.0.118,org.apache.tomcat.embed:tomcat-embed-core:9.0.118
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Publish Date: 2026-04-09
URL: CVE-2026-34487
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-04-09
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.21
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.6
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Path to dependency file: /build.gradle.kts
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c
Found in base branch: master
Vulnerability Details
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
Publish Date: 2026-04-09
URL: CVE-2026-34483
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-04-09
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.21
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.6
Step up your Open Source Security Game with Mend here