Skip to content

spring-boot-starter-web-4.0.4.jar: 65 vulnerabilities (highest severity is: 9.8) #53

Description

@mend-bolt-for-github
Vulnerable Library - spring-boot-starter-web-4.0.4.jar

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-databind/3.1.0/59a342020cc4f5a49335c16820be6ed8ca8ee6c7/jackson-databind-3.1.0.jar

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (spring-boot-starter-web version) Remediation Possible**
CVE-2026-65905 Critical 9.8 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-47891 Critical 9.8 spring-web-7.0.6.jar Transitive N/A*
CVE-2026-47890 Critical 9.8 spring-webmvc-7.0.6.jar Transitive N/A*
CVE-2026-47884 Critical 9.8 spring-webmvc-7.0.6.jar Transitive N/A*
CVE-2026-43512 Critical 9.8 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-41293 Critical 9.8 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-68525 Critical 9.1 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-65182 Critical 9.1 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-59084 Critical 9.1 tomcat-embed-core-11.0.18.jar Transitive 4.0.8
CVE-2026-59083 Critical 9.1 tomcat-embed-core-11.0.18.jar Transitive 4.0.8
CVE-2026-43515 Critical 9.1 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-40976 Critical 9.1 spring-boot-4.0.4.jar Transitive N/A*
CVE-2026-29145 Critical 9.1 tomcat-embed-core-11.0.18.jar Transitive 4.0.5
CVE-2026-68569 High 8.1 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-66422 High 8.1 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-65183 High 8.1 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-54513 High 8.1 jackson-databind-3.1.0.jar Transitive N/A*
CVE-2026-54512 High 8.1 jackson-databind-3.1.0.jar Transitive N/A*
CVE-2026-68763 High 7.5 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-65927 High 7.5 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-47889 High 7.5 spring-web-7.0.6.jar Transitive N/A*
CVE-2026-47886 High 7.5 spring-expression-7.0.6.jar Transitive N/A*
CVE-2026-47885 High 7.5 spring-web-7.0.6.jar Transitive N/A*
CVE-2026-43513 High 7.5 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-41850 High 7.5 spring-expression-7.0.6.jar Transitive 4.0.7
CVE-2026-41842 High 7.5 spring-webmvc-7.0.6.jar Transitive 4.0.7
CVE-2026-41284 High 7.5 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-34487 High 7.5 tomcat-embed-core-11.0.18.jar Transitive 4.0.6
CVE-2026-34483 High 7.5 tomcat-embed-core-11.0.18.jar Transitive 4.0.6
CVE-2026-29146 High 7.5 tomcat-embed-core-11.0.18.jar Transitive 4.0.5
CVE-2026-29129 High 7.5 tomcat-embed-core-11.0.18.jar Transitive 4.0.5
CVE-2026-24880 High 7.5 tomcat-embed-core-11.0.18.jar Transitive 4.0.5
CVE-2026-42498 High 7.3 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-41845 High 7.1 detected in multiple dependencies Transitive 4.0.7
CVE-2026-40973 High 7.0 spring-boot-4.0.4.jar Transitive 4.0.6
CVE-2026-73180 Medium 6.8 tomcat-embed-websocket-11.0.18.jar Transitive N/A*
CVE-2026-59889 Medium 6.5 jackson-databind-3.1.0.jar Transitive 4.0.8
CVE-2026-59888 Medium 6.5 jackson-databind-3.1.0.jar Transitive 4.0.7
CVE-2026-54518 Medium 6.5 jackson-databind-3.1.0.jar Transitive N/A*
CVE-2026-22740 Medium 6.5 spring-web-7.0.6.jar Transitive 4.0.6
CVE-2026-47887 Medium 6.1 spring-webmvc-7.0.6.jar Transitive N/A*
CVE-2026-47883 Medium 6.1 spring-web-7.0.6.jar Transitive N/A*
CVE-2026-25854 Medium 6.1 tomcat-embed-core-11.0.18.jar Transitive 4.0.5
CVE-2026-41846 Medium 5.9 spring-webmvc-7.0.6.jar Transitive 4.0.7
CVE-2026-41843 Medium 5.9 spring-webmvc-7.0.6.jar Transitive 4.0.7
CVE-2026-41841 Medium 5.9 spring-webmvc-7.0.6.jar Transitive 4.0.7
CVE-2026-41840 Medium 5.9 spring-web-7.0.6.jar Transitive 4.0.7
CVE-2026-77310 Medium 5.3 jackson-databind-3.1.0.jar Transitive 4.0.8
CVE-2026-54517 Medium 5.3 jackson-databind-3.1.0.jar Transitive N/A*
CVE-2026-54516 Medium 5.3 jackson-databind-3.1.0.jar Transitive N/A*
CVE-2026-54515 Medium 5.3 jackson-databind-3.1.0.jar Transitive N/A*
CVE-2026-54514 Medium 5.3 jackson-databind-3.1.0.jar Transitive N/A*
CVE-2026-41853 Medium 5.3 detected in multiple dependencies Transitive N/A*
CVE-2026-41851 Medium 5.3 spring-expression-7.0.6.jar Transitive 4.0.7
CVE-2026-32990 Medium 5.3 tomcat-embed-core-11.0.18.jar Transitive 4.0.5
CVE-2026-22745 Medium 5.3 spring-webmvc-7.0.6.jar Transitive 4.0.6
CVE-2026-40975 Medium 4.8 spring-boot-4.0.4.jar Transitive 4.0.6
CVE-2026-40977 Medium 4.7 spring-boot-4.0.4.jar Transitive 4.0.6
CVE-2026-41854 Medium 4.2 spring-web-7.0.6.jar Transitive 4.0.7
CVE-2026-41844 Medium 4.2 spring-webmvc-7.0.6.jar Transitive 4.0.7
CVE-2026-41839 Medium 4.2 spring-web-7.0.6.jar Transitive 4.0.7
CVE-2026-43514 Low 3.7 tomcat-embed-core-11.0.18.jar Transitive N/A*
CVE-2026-41852 Low 3.7 spring-expression-7.0.6.jar Transitive 4.0.7
CVE-2026-41848 Low 3.7 spring-core-7.0.6.jar Transitive 4.0.7
CVE-2026-22741 Low 3.1 spring-webmvc-7.0.6.jar Transitive 4.0.6

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

Partial details (17 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.

CVE-2026-65905

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while the
associated nonceCount remains within the replay window.
 
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

Publish Date: 2026-08-25

URL: CVE-2026-65905

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,org.apache.tomcat:tomcat-catalina:10.1.59,https://github.com/apache/tomcat.git - 11.0.25,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,https://github.com/apache/tomcat.git - 9.0.121,https://github.com/apache/tomcat.git - 10.1.58

Step up your Open Source Security Game with Mend here

CVE-2026-47891

Vulnerable Library - spring-web-7.0.6.jar

Spring Web

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-web/7.0.6/2baeb353efd42374239cc45e8d02780d6c6e7a77/spring-web-7.0.6.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-http-converter-4.0.4.jar
      • spring-web-7.0.6.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier

Publish Date: 2026-08-27

URL: CVE-2026-47891

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-27

Fix Resolution: https://github.com/spring-projects/spring-framework.git - v7.0.9,org.springframework:spring-web:7.0.9

Step up your Open Source Security Game with Mend here

CVE-2026-47890

Vulnerable Library - spring-webmvc-7.0.6.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-webmvc-4.0.4.jar
      • spring-webmvc-7.0.6.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19

Publish Date: 2026-08-27

URL: CVE-2026-47890

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2026-47890

Release Date: 2026-08-27

Fix Resolution: org.springframework:spring-webmvc:7.0.9,org.springframework:spring-webflux:7.0.9

Step up your Open Source Security Game with Mend here

CVE-2026-47884

Vulnerable Library - spring-webmvc-7.0.6.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-webmvc-4.0.4.jar
      • spring-webmvc-7.0.6.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-08-27

URL: CVE-2026-47884

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-27

Fix Resolution: https://github.com/spring-projects/spring-framework.git - v7.0.9,org.springframework:spring-webmvc:7.0.9

Step up your Open Source Security Game with Mend here

CVE-2026-43512

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0.
Older unsupported versions any also be affect
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

Publish Date: 2026-05-12

URL: CVE-2026-43512

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-12

Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat:tomcat-catalina:11.0.22,org.apache.tomcat:tomcat-catalina:9.0.118,org.apache.tomcat:tomcat-catalina:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,https://github.com/apache/tomcat.git - 9.0.118

Step up your Open Source Security Game with Mend here

CVE-2026-41293

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Improper Input Validation vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27.
Older, end of support versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

Publish Date: 2026-05-12

URL: CVE-2026-41293

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-12

Fix Resolution: org.apache.tomcat:tomcat-coyote:9.0.118,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-coyote:11.0.22,org.apache.tomcat:tomcat-coyote:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 9.0.118,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118

Step up your Open Source Security Game with Mend here

CVE-2026-68525

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

Publish Date: 2026-08-25

URL: CVE-2026-68525

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,org.apache.tomcat:tomcat-catalina:10.1.59,https://github.com/apache/tomcat.git - 9.0.121,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,https://github.com/apache/tomcat.git - 10.1.58,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:11.0.25

Step up your Open Source Security Game with Mend here

CVE-2026-65182

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.

Publish Date: 2026-08-25

URL: CVE-2026-65182

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:11.0.25,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat:tomcat-catalina:10.1.59,org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,https://github.com/apache/tomcat.git - 10.1.58,https://github.com/apache/tomcat.git - 9.0.121

Step up your Open Source Security Game with Mend here

CVE-2026-59084

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

Publish Date: 2026-07-14

URL: CVE-2026-59084

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7

Release Date: 2026-07-14

Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.24

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8

Step up your Open Source Security Game with Mend here

CVE-2026-59083

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

Publish Date: 2026-07-14

URL: CVE-2026-59083

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-14

Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.24

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8

Step up your Open Source Security Game with Mend here

CVE-2026-43515

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

Publish Date: 2026-05-12

URL: CVE-2026-43515

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-12

Fix Resolution: org.apache.tomcat:tomcat-catalina:11.0.22,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-catalina:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,org.apache.tomcat:tomcat-catalina:9.0.118,https://github.com/apache/tomcat.git - 9.0.118

Step up your Open Source Security Game with Mend here

CVE-2026-40976

Vulnerable Library - spring-boot-4.0.4.jar

Spring Boot

Library home page: https://spring.io/projects/spring-boot

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework.boot/spring-boot/4.0.4/93d6e7c5b747d640bbad17971c5ce957bee88c5f/spring-boot-4.0.4.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-http-converter-4.0.4.jar
      • spring-boot-4.0.4.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

Publish Date: 2026-04-27

URL: CVE-2026-40976

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-04-27

Fix Resolution: org.springframework.boot:spring-boot-security:4.0.6,https://github.com/spring-projects/spring-boot.git - v4.0.6

Step up your Open Source Security Game with Mend here

CVE-2026-29145

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13.
Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

Publish Date: 2026-04-09

URL: CVE-2026-29145

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-04-09

Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.20

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.5

Step up your Open Source Security Game with Mend here

CVE-2026-68569

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

Publish Date: 2026-08-25

URL: CVE-2026-68569

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat:tomcat-catalina:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 10.1.58,https://github.com/apache/tomcat.git - 11.0.25,https://github.com/apache/tomcat.git - 9.0.121

Step up your Open Source Security Game with Mend here

CVE-2026-66422

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole().
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

Publish Date: 2026-08-25

URL: CVE-2026-66422

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: org.apache.tomcat:tomcat-catalina:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,https://github.com/apache/tomcat.git - 10.1.58,org.apache.tomcat:tomcat-catalina:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,https://github.com/apache/tomcat.git - 9.0.121,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59

Step up your Open Source Security Game with Mend here

CVE-2026-65183

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.

Publish Date: 2026-08-25

URL: CVE-2026-65183

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: org.apache.tomcat:tomcat-coyote:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,org.apache.tomcat:tomcat-coyote:10.1.59,https://github.com/apache/tomcat.git - 10.1.58,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,org.apache.tomcat:tomcat-coyote:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,https://github.com/apache/tomcat.git - 9.0.121

Step up your Open Source Security Game with Mend here

CVE-2026-54513

Vulnerable Library - jackson-databind-3.1.0.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: https://github.com/FasterXML/jackson

Sample Path to Dependency File: /build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/tools.jackson.core/jackson-databind/3.1.0/59a342020cc4f5a49335c16820be6ed8ca8ee6c7/jackson-databind-3.1.0.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-jackson-4.0.4.jar
      • spring-boot-jackson-4.0.4.jar
        • jackson-databind-3.1.0.jar (Vulnerable Library)

Found in HEAD commit: 29e5aeedb20278d4c2d9ff41b8322b5115b86941

Found in base branch: master

Vulnerability Details

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

Publish Date: 2026-06-23

URL: CVE-2026-54513

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-06-23

Fix Resolution: https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4

Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions