Vulnerable Library - spring-boot-starter-web-4.0.4.jar
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-databind/3.1.0/59a342020cc4f5a49335c16820be6ed8ca8ee6c7/jackson-databind-3.1.0.jar
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Dependency |
Type |
Fixed in (spring-boot-starter-web version) |
Remediation Possible** |
| CVE-2026-65905 |
Critical |
9.8 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-47891 |
Critical |
9.8 |
spring-web-7.0.6.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-47890 |
Critical |
9.8 |
spring-webmvc-7.0.6.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-47884 |
Critical |
9.8 |
spring-webmvc-7.0.6.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-43512 |
Critical |
9.8 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-41293 |
Critical |
9.8 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-68525 |
Critical |
9.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-65182 |
Critical |
9.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-59084 |
Critical |
9.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.8 |
❌ |
| CVE-2026-59083 |
Critical |
9.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.8 |
❌ |
| CVE-2026-43515 |
Critical |
9.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-40976 |
Critical |
9.1 |
spring-boot-4.0.4.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-29145 |
Critical |
9.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-68569 |
High |
8.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-66422 |
High |
8.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-65183 |
High |
8.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-54513 |
High |
8.1 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-54512 |
High |
8.1 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-68763 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-65927 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-47889 |
High |
7.5 |
spring-web-7.0.6.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-47886 |
High |
7.5 |
spring-expression-7.0.6.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-47885 |
High |
7.5 |
spring-web-7.0.6.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-43513 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-41850 |
High |
7.5 |
spring-expression-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41842 |
High |
7.5 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41284 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-34487 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-34483 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-29146 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-29129 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-24880 |
High |
7.5 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-42498 |
High |
7.3 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-41845 |
High |
7.1 |
detected in multiple dependencies |
Transitive |
4.0.7 |
❌ |
| CVE-2026-40973 |
High |
7.0 |
spring-boot-4.0.4.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-73180 |
Medium |
6.8 |
tomcat-embed-websocket-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-59889 |
Medium |
6.5 |
jackson-databind-3.1.0.jar |
Transitive |
4.0.8 |
❌ |
| CVE-2026-59888 |
Medium |
6.5 |
jackson-databind-3.1.0.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-54518 |
Medium |
6.5 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-22740 |
Medium |
6.5 |
spring-web-7.0.6.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-47887 |
Medium |
6.1 |
spring-webmvc-7.0.6.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-47883 |
Medium |
6.1 |
spring-web-7.0.6.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-25854 |
Medium |
6.1 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-41846 |
Medium |
5.9 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41843 |
Medium |
5.9 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41841 |
Medium |
5.9 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41840 |
Medium |
5.9 |
spring-web-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-77310 |
Medium |
5.3 |
jackson-databind-3.1.0.jar |
Transitive |
4.0.8 |
❌ |
| CVE-2026-54517 |
Medium |
5.3 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-54516 |
Medium |
5.3 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-54515 |
Medium |
5.3 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-54514 |
Medium |
5.3 |
jackson-databind-3.1.0.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-41853 |
Medium |
5.3 |
detected in multiple dependencies |
Transitive |
N/A* |
❌ |
| CVE-2026-41851 |
Medium |
5.3 |
spring-expression-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-32990 |
Medium |
5.3 |
tomcat-embed-core-11.0.18.jar |
Transitive |
4.0.5 |
❌ |
| CVE-2026-22745 |
Medium |
5.3 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-40975 |
Medium |
4.8 |
spring-boot-4.0.4.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-40977 |
Medium |
4.7 |
spring-boot-4.0.4.jar |
Transitive |
4.0.6 |
❌ |
| CVE-2026-41854 |
Medium |
4.2 |
spring-web-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41844 |
Medium |
4.2 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41839 |
Medium |
4.2 |
spring-web-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-43514 |
Low |
3.7 |
tomcat-embed-core-11.0.18.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-41852 |
Low |
3.7 |
spring-expression-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-41848 |
Low |
3.7 |
spring-core-7.0.6.jar |
Transitive |
4.0.7 |
❌ |
| CVE-2026-22741 |
Low |
3.1 |
spring-webmvc-7.0.6.jar |
Transitive |
4.0.6 |
❌ |
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Partial details (17 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.
CVE-2026-65905
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while the
associated nonceCount remains within the replay window.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Publish Date: 2026-08-25
URL: CVE-2026-65905
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,org.apache.tomcat:tomcat-catalina:10.1.59,https://github.com/apache/tomcat.git - 11.0.25,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,https://github.com/apache/tomcat.git - 9.0.121,https://github.com/apache/tomcat.git - 10.1.58
Step up your Open Source Security Game with Mend here
CVE-2026-47891
Vulnerable Library - spring-web-7.0.6.jar
Spring Web
Library home page: https://github.com/spring-projects/spring-framework
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-web/7.0.6/2baeb353efd42374239cc45e8d02780d6c6e7a77/spring-web-7.0.6.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-http-converter-4.0.4.jar
- ❌ spring-web-7.0.6.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Publish Date: 2026-08-27
URL: CVE-2026-47891
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-27
Fix Resolution: https://github.com/spring-projects/spring-framework.git - v7.0.9,org.springframework:spring-web:7.0.9
Step up your Open Source Security Game with Mend here
CVE-2026-47890
Vulnerable Library - spring-webmvc-7.0.6.jar
Spring Web MVC
Library home page: https://github.com/spring-projects/spring-framework
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-webmvc-4.0.4.jar
- ❌ spring-webmvc-7.0.6.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Publish Date: 2026-08-27
URL: CVE-2026-47890
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://spring.io/security/cve-2026-47890
Release Date: 2026-08-27
Fix Resolution: org.springframework:spring-webmvc:7.0.9,org.springframework:spring-webflux:7.0.9
Step up your Open Source Security Game with Mend here
CVE-2026-47884
Vulnerable Library - spring-webmvc-7.0.6.jar
Spring Web MVC
Library home page: https://github.com/spring-projects/spring-framework
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-webmvc-4.0.4.jar
- ❌ spring-webmvc-7.0.6.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: 2026-08-27
URL: CVE-2026-47884
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-27
Fix Resolution: https://github.com/spring-projects/spring-framework.git - v7.0.9,org.springframework:spring-webmvc:7.0.9
Step up your Open Source Security Game with Mend here
CVE-2026-43512
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0.
Older unsupported versions any also be affect
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Publish Date: 2026-05-12
URL: CVE-2026-43512
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat:tomcat-catalina:11.0.22,org.apache.tomcat:tomcat-catalina:9.0.118,org.apache.tomcat:tomcat-catalina:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,https://github.com/apache/tomcat.git - 9.0.118
Step up your Open Source Security Game with Mend here
CVE-2026-41293
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Input Validation vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27.
Older, end of support versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Publish Date: 2026-05-12
URL: CVE-2026-41293
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat:tomcat-coyote:9.0.118,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-coyote:11.0.22,org.apache.tomcat:tomcat-coyote:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 9.0.118,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118
Step up your Open Source Security Game with Mend here
CVE-2026-68525
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.
Publish Date: 2026-08-25
URL: CVE-2026-68525
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,org.apache.tomcat:tomcat-catalina:10.1.59,https://github.com/apache/tomcat.git - 9.0.121,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,https://github.com/apache/tomcat.git - 10.1.58,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:11.0.25
Step up your Open Source Security Game with Mend here
CVE-2026-65182
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
Publish Date: 2026-08-25
URL: CVE-2026-65182
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:11.0.25,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat:tomcat-catalina:10.1.59,org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,https://github.com/apache/tomcat.git - 10.1.58,https://github.com/apache/tomcat.git - 9.0.121
Step up your Open Source Security Game with Mend here
CVE-2026-59084
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
Publish Date: 2026-07-14
URL: CVE-2026-59084
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7
Release Date: 2026-07-14
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.24
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8
Step up your Open Source Security Game with Mend here
CVE-2026-59083
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
Publish Date: 2026-07-14
URL: CVE-2026-59083
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-07-14
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.24
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8
Step up your Open Source Security Game with Mend here
CVE-2026-43515
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Publish Date: 2026-05-12
URL: CVE-2026-43515
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat:tomcat-catalina:11.0.22,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-catalina:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,org.apache.tomcat:tomcat-catalina:9.0.118,https://github.com/apache/tomcat.git - 9.0.118
Step up your Open Source Security Game with Mend here
CVE-2026-40976
Vulnerable Library - spring-boot-4.0.4.jar
Spring Boot
Library home page: https://spring.io/projects/spring-boot
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework.boot/spring-boot/4.0.4/93d6e7c5b747d640bbad17971c5ce957bee88c5f/spring-boot-4.0.4.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-http-converter-4.0.4.jar
- ❌ spring-boot-4.0.4.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
Publish Date: 2026-04-27
URL: CVE-2026-40976
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-04-27
Fix Resolution: org.springframework.boot:spring-boot-security:4.0.6,https://github.com/spring-projects/spring-boot.git - v4.0.6
Step up your Open Source Security Game with Mend here
CVE-2026-29145
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13.
Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
Publish Date: 2026-04-09
URL: CVE-2026-29145
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-04-09
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.20
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.5
Step up your Open Source Security Game with Mend here
CVE-2026-68569
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Publish Date: 2026-08-25
URL: CVE-2026-68569
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat:tomcat-catalina:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 10.1.58,https://github.com/apache/tomcat.git - 11.0.25,https://github.com/apache/tomcat.git - 9.0.121
Step up your Open Source Security Game with Mend here
CVE-2026-66422
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole().
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Publish Date: 2026-08-25
URL: CVE-2026-66422
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat:tomcat-catalina:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,https://github.com/apache/tomcat.git - 10.1.58,org.apache.tomcat:tomcat-catalina:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,https://github.com/apache/tomcat.git - 9.0.121,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59
Step up your Open Source Security Game with Mend here
CVE-2026-65183
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-tomcat-4.0.4.jar
- spring-boot-starter-tomcat-runtime-4.0.4.jar
- ❌ tomcat-embed-core-11.0.18.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
Publish Date: 2026-08-25
URL: CVE-2026-65183
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat:tomcat-coyote:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,org.apache.tomcat:tomcat-coyote:10.1.59,https://github.com/apache/tomcat.git - 10.1.58,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,org.apache.tomcat:tomcat-coyote:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,https://github.com/apache/tomcat.git - 9.0.121
Step up your Open Source Security Game with Mend here
CVE-2026-54513
Vulnerable Library - jackson-databind-3.1.0.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: https://github.com/FasterXML/jackson
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-databind/3.1.0/59a342020cc4f5a49335c16820be6ed8ca8ee6c7/jackson-databind-3.1.0.jar
Dependency Hierarchy:
- spring-boot-starter-web-4.0.4.jar (Root Library)
- spring-boot-starter-jackson-4.0.4.jar
- spring-boot-jackson-4.0.4.jar
- ❌ jackson-databind-3.1.0.jar (Vulnerable Library)
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Publish Date: 2026-06-23
URL: CVE-2026-54513
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-06-23
Fix Resolution: https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4
Step up your Open Source Security Game with Mend here
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-databind/3.1.0/59a342020cc4f5a49335c16820be6ed8ca8ee6c7/jackson-databind-3.1.0.jar
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while the
associated nonceCount remains within the replay window.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Publish Date: 2026-08-25
URL: CVE-2026-65905
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,org.apache.tomcat:tomcat-catalina:10.1.59,https://github.com/apache/tomcat.git - 11.0.25,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,https://github.com/apache/tomcat.git - 9.0.121,https://github.com/apache/tomcat.git - 10.1.58
Step up your Open Source Security Game with Mend here
Vulnerable Library - spring-web-7.0.6.jar
Spring Web
Library home page: https://github.com/spring-projects/spring-framework
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-web/7.0.6/2baeb353efd42374239cc45e8d02780d6c6e7a77/spring-web-7.0.6.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Publish Date: 2026-08-27
URL: CVE-2026-47891
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-27
Fix Resolution: https://github.com/spring-projects/spring-framework.git - v7.0.9,org.springframework:spring-web:7.0.9
Step up your Open Source Security Game with Mend here
Vulnerable Library - spring-webmvc-7.0.6.jar
Spring Web MVC
Library home page: https://github.com/spring-projects/spring-framework
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Publish Date: 2026-08-27
URL: CVE-2026-47890
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://spring.io/security/cve-2026-47890
Release Date: 2026-08-27
Fix Resolution: org.springframework:spring-webmvc:7.0.9,org.springframework:spring-webflux:7.0.9
Step up your Open Source Security Game with Mend here
Vulnerable Library - spring-webmvc-7.0.6.jar
Spring Web MVC
Library home page: https://github.com/spring-projects/spring-framework
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: 2026-08-27
URL: CVE-2026-47884
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-27
Fix Resolution: https://github.com/spring-projects/spring-framework.git - v7.0.9,org.springframework:spring-webmvc:7.0.9
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0.
Older unsupported versions any also be affect
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Publish Date: 2026-05-12
URL: CVE-2026-43512
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat:tomcat-catalina:11.0.22,org.apache.tomcat:tomcat-catalina:9.0.118,org.apache.tomcat:tomcat-catalina:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,https://github.com/apache/tomcat.git - 9.0.118
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Input Validation vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27.
Older, end of support versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Publish Date: 2026-05-12
URL: CVE-2026-41293
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat:tomcat-coyote:9.0.118,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-coyote:11.0.22,org.apache.tomcat:tomcat-coyote:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 9.0.118,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.
Publish Date: 2026-08-25
URL: CVE-2026-68525
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,org.apache.tomcat:tomcat-catalina:10.1.59,https://github.com/apache/tomcat.git - 9.0.121,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,https://github.com/apache/tomcat.git - 10.1.58,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:11.0.25
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
Publish Date: 2026-08-25
URL: CVE-2026-65182
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:11.0.25,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat:tomcat-catalina:10.1.59,org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,https://github.com/apache/tomcat.git - 10.1.58,https://github.com/apache/tomcat.git - 9.0.121
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
Publish Date: 2026-07-14
URL: CVE-2026-59084
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7
Release Date: 2026-07-14
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.24
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
Publish Date: 2026-07-14
URL: CVE-2026-59083
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-07-14
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.24
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Publish Date: 2026-05-12
URL: CVE-2026-43515
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-05-12
Fix Resolution: org.apache.tomcat:tomcat-catalina:11.0.22,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-catalina:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,org.apache.tomcat:tomcat-catalina:9.0.118,https://github.com/apache/tomcat.git - 9.0.118
Step up your Open Source Security Game with Mend here
Vulnerable Library - spring-boot-4.0.4.jar
Spring Boot
Library home page: https://spring.io/projects/spring-boot
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework.boot/spring-boot/4.0.4/93d6e7c5b747d640bbad17971c5ce957bee88c5f/spring-boot-4.0.4.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
Publish Date: 2026-04-27
URL: CVE-2026-40976
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-04-27
Fix Resolution: org.springframework.boot:spring-boot-security:4.0.6,https://github.com/spring-projects/spring-boot.git - v4.0.6
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13.
Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
Publish Date: 2026-04-09
URL: CVE-2026-29145
CVSS 3 Score Details (9.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-04-09
Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.20
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.5
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Publish Date: 2026-08-25
URL: CVE-2026-68569
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat:tomcat-catalina:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 10.1.58,https://github.com/apache/tomcat.git - 11.0.25,https://github.com/apache/tomcat.git - 9.0.121
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole().
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Publish Date: 2026-08-25
URL: CVE-2026-66422
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat:tomcat-catalina:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,https://github.com/apache/tomcat.git - 10.1.58,org.apache.tomcat:tomcat-catalina:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,https://github.com/apache/tomcat.git - 9.0.121,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59
Step up your Open Source Security Game with Mend here
Vulnerable Library - tomcat-embed-core-11.0.18.jar
Core Tomcat implementation
Library home page: https://tomcat.apache.org/
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
Publish Date: 2026-08-25
URL: CVE-2026-65183
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: org.apache.tomcat:tomcat-coyote:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,org.apache.tomcat:tomcat-coyote:10.1.59,https://github.com/apache/tomcat.git - 10.1.58,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,org.apache.tomcat:tomcat-coyote:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,https://github.com/apache/tomcat.git - 9.0.121
Step up your Open Source Security Game with Mend here
Vulnerable Library - jackson-databind-3.1.0.jar
General data-binding functionality for Jackson: works on core streaming API
Library home page: https://github.com/FasterXML/jackson
Sample Path to Dependency File: /build.gradle
Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-databind/3.1.0/59a342020cc4f5a49335c16820be6ed8ca8ee6c7/jackson-databind-3.1.0.jar
Dependency Hierarchy:
Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941
Found in base branch: master
Vulnerability Details
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Publish Date: 2026-06-23
URL: CVE-2026-54513
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-06-23
Fix Resolution: https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4
Step up your Open Source Security Game with Mend here