Skip to content

spring-boot-starter-web-2.7.1.jar: 36 vulnerabilities (highest severity is: 9.8) reachable #37

Description

@mend-for-github-com
Vulnerable Library - spring-boot-starter-web-2.7.1.jar

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.21/spring-web-5.3.21.jar

Vulnerabilities

Vulnerability Severity CVSS Exploit Maturity EPSS Dependency Type Fixed in (spring-boot-starter-web version) Remediation Possible** Reachability
CVE-2024-22262 High 8.1 Not Defined 1.191% spring-web-5.3.21.jar Transitive 3.0.0

Reachable

CVE-2024-22259 High 8.1 Not Defined 2.573% spring-web-5.3.21.jar Transitive 3.0.0

Reachable

CVE-2024-22243 High 8.1 Not Defined 3.967% spring-web-5.3.21.jar Transitive 3.0.0

Reachable

WS-2026-0003 High 7.5 Not Defined jackson-core-2.13.3.jar Transitive 3.5.0

Reachable

WS-2022-0468 High 7.5 Not Defined jackson-core-2.13.3.jar Transitive 3.1.0

Reachable

CVE-2025-52999 High 7.5 Not Defined 0.634% jackson-core-2.13.3.jar Transitive 3.1.0

Reachable

CVE-2024-38819 High 7.5 Not Defined 54.862% spring-webmvc-5.3.21.jar Transitive 3.2.11

Reachable

CVE-2024-38816 High 7.5 Not Defined 14.718% spring-webmvc-5.3.21.jar Transitive 3.2.10

Reachable

CVE-2023-20860 High 7.5 Not Defined 3.514% spring-webmvc-5.3.21.jar Transitive 2.7.10

Reachable

CVE-2022-42004 High 7.5 Not Defined 2.766% jackson-databind-2.13.3.jar Transitive 2.7.4

Reachable

CVE-2022-42003 High 7.5 Not Defined 2.766% jackson-databind-2.13.3.jar Transitive 2.7.9

Reachable

CVE-2026-22740 Medium 6.5 Not Defined 0.344% spring-web-5.3.21.jar Transitive N/A*

Reachable

CVE-2026-22737 Medium 5.9 Not Defined 0.385% spring-webmvc-5.3.21.jar Transitive N/A*

Reachable

CVE-2025-41242 Medium 5.9 Not Defined 2.054% spring-webmvc-5.3.21.jar Transitive N/A*

Reachable

CVE-2026-22745 Medium 5.3 Not Defined 0.341% spring-webmvc-5.3.21.jar Transitive 3.5.14

Reachable

CVE-2024-38828 Medium 5.3 Not Defined 0.729% detected in multiple dependencies Transitive N/A*

Reachable

CVE-2024-38809 Medium 5.3 Not Defined 0.852% spring-web-5.3.21.jar Transitive 3.0.0

Reachable

CVE-2026-22741 Low 3.1 Not Defined 0.236% spring-webmvc-5.3.21.jar Transitive N/A*

Reachable

CVE-2024-38820 Low 3.1 Not Defined 0.617% detected in multiple dependencies Transitive N/A*

Reachable

CVE-2026-22735 Low 2.6 Not Defined 0.112% detected in multiple dependencies Transitive N/A*

Reachable

CVE-2016-1000027 Critical 9.8 Not Defined 32.257% spring-web-5.3.21.jar Transitive 3.0.0

Unreachable

CVE-2026-54513 High 8.1 Not Defined 0.712% jackson-databind-2.13.3.jar Transitive N/A*
CVE-2026-54512 High 8.1 Not Defined 0.779% jackson-databind-2.13.3.jar Transitive N/A*
CVE-2026-68494 High 7.5 Not Defined jackson-core-2.13.3.jar Transitive 3.5.0
CVE-2026-41842 High 7.5 Not Defined 0.399% spring-webmvc-5.3.21.jar Transitive N/A*
CVE-2026-41845 High 7.1 Not Defined 0.161% detected in multiple dependencies Transitive N/A*
CVE-2026-41846 Medium 5.9 Not Defined 0.14% spring-webmvc-5.3.21.jar Transitive N/A*
CVE-2026-41843 Medium 5.9 Not Defined 0.341% spring-webmvc-5.3.21.jar Transitive N/A*
CVE-2026-41841 Medium 5.9 Not Defined 0.313% spring-webmvc-5.3.21.jar Transitive N/A*
CVE-2026-41840 Medium 5.9 Not Defined 0.247% spring-web-5.3.21.jar Transitive N/A*
CVE-2026-54515 Medium 5.3 Not Defined 0.345% jackson-databind-2.13.3.jar Transitive N/A*
CVE-2026-54514 Medium 5.3 Not Defined 0.219% jackson-databind-2.13.3.jar Transitive N/A*
CVE-2026-50193 Medium 5.3 Not Defined 0.459% jackson-databind-2.13.3.jar Transitive N/A*
CVE-2026-41853 Medium 5.3 Not Defined 0.186% detected in multiple dependencies Transitive N/A*
CVE-2026-41844 Medium 4.2 Not Defined 0.134% spring-webmvc-5.3.21.jar Transitive N/A*
CVE-2026-41839 Medium 4.2 Not Defined 0.197% spring-web-5.3.21.jar Transitive N/A*

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

Partial details (16 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.

CVE-2024-22262

Vulnerable Library - spring-web-5.3.21.jar

Spring Web

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.21/spring-web-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-boot-starter-json-2.7.1.jar
      • spring-web-5.3.21.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.webwolf.FileServer (Application)
  -> org.springframework.web.servlet.view.RedirectView (Extension)
   -> ❌ org.springframework.web.util.UriComponentsBuilder (Vulnerable Component)

Vulnerability Details

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259  and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.

Publish Date: 2024-04-16

URL: CVE-2024-22262

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 1.191%

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2024-22262

Release Date: 2024-04-16

Fix Resolution (org.springframework:spring-web): 5.3.34

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.0.0

In order to enable automatic remediation, please create workflow rules

CVE-2024-22259

Vulnerable Library - spring-web-5.3.21.jar

Spring Web

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.21/spring-web-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-boot-starter-json-2.7.1.jar
      • spring-web-5.3.21.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.webwolf.FileServer (Application)
  -> org.springframework.web.servlet.view.RedirectView (Extension)
   -> ❌ org.springframework.web.util.UriComponentsBuilder (Vulnerable Component)

Vulnerability Details

Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.

Publish Date: 2024-03-16

URL: CVE-2024-22259

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 2.573%

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2024-22259

Release Date: 2024-03-16

Fix Resolution (org.springframework:spring-web): 5.3.33

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.0.0

In order to enable automatic remediation, please create workflow rules

CVE-2024-22243

Vulnerable Library - spring-web-5.3.21.jar

Spring Web

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.21/spring-web-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-boot-starter-json-2.7.1.jar
      • spring-web-5.3.21.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.webwolf.FileServer (Application)
  -> org.springframework.web.servlet.view.RedirectView (Extension)
   -> ❌ org.springframework.web.util.UriComponentsBuilder (Vulnerable Component)

Vulnerability Details

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.

Publish Date: 2024-02-23

URL: CVE-2024-22243

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 3.967%

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2024-22243

Release Date: 2024-02-23

Fix Resolution (org.springframework:spring-web): 5.3.32

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.0.0

In order to enable automatic remediation, please create workflow rules

WS-2026-0003

Vulnerable Library - jackson-core-2.13.3.jar

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.3/jackson-core-2.13.3.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-boot-starter-json-2.7.1.jar
      • jackson-databind-2.13.3.jar
        • jackson-core-2.13.3.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.lessons.xss.stored.StoredXssComments (Application)
  -> com.fasterxml.jackson.databind.ObjectMapper (Extension)
   -> ❌ com.fasterxml.jackson.core.Base64Variant (Vulnerable Component)

Vulnerability Details

The non-blocking (async) JSON parser in jackson-core bypasses the maxNumberLength constraint (default: 1000 characters) defined in StreamReadConstraints. This allows an attacker to send JSON with arbitrarily long numbers through the async parser API, leading to excessive memory allocation and potential CPU exhaustion, resulting in a Denial of Service (DoS).

The standard synchronous parser correctly enforces this limit, but the async parser fails to do so, creating an inconsistent enforcement policy.

Publish Date: 2026-03-02

URL: WS-2026-0003

Threat Assessment

Exploit Maturity: Not Defined

EPSS:

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-72hv-8253-57qq

Release Date: 2026-03-02

Fix Resolution (com.fasterxml.jackson.core:jackson-core): 2.18.6

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.5.0

In order to enable automatic remediation, please create workflow rules

WS-2022-0468

Vulnerable Library - jackson-core-2.13.3.jar

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.3/jackson-core-2.13.3.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-boot-starter-json-2.7.1.jar
      • jackson-databind-2.13.3.jar
        • jackson-core-2.13.3.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.lessons.csrf.CSRFFeedback (Application)
  -> com.fasterxml.jackson.databind.ObjectMapper (Extension)
   -> com.fasterxml.jackson.core.io.SegmentedStringWriter (Extension)
    -> ❌ com.fasterxml.jackson.core.util.TextBuffer (Vulnerable Component)

Vulnerability Details

The jackson-core package is vulnerable to a Denial of Service (DoS) attack. The methods in the classes listed below fail to restrict input size when performing numeric type conversions. A remote attacker can exploit this vulnerability by causing the application to deserialize data containing certain numeric types with large values. Deserializing many of the aforementioned objects may cause the application to exhaust all available resources, resulting in a DoS condition.

Publish Date: 2026-05-20

URL: WS-2022-0468

Threat Assessment

Exploit Maturity: Not Defined

EPSS:

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2022-12-07

Fix Resolution (com.fasterxml.jackson.core:jackson-core): 2.15.0-rc1

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.1.0

In order to enable automatic remediation, please create workflow rules

CVE-2025-52999

Vulnerable Library - jackson-core-2.13.3.jar

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.3/jackson-core-2.13.3.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-boot-starter-json-2.7.1.jar
      • jackson-databind-2.13.3.jar
        • jackson-core-2.13.3.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.JWTLessonIntegrationTest (Application)
  -> com.fasterxml.jackson.databind.JsonNode (Extension)
   -> com.fasterxml.jackson.core.JsonGenerator (Extension)
    -> ❌ com.fasterxml.jackson.core.json.JsonReadContext (Vulnerable Component)

Vulnerability Details

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.

Publish Date: 2025-06-25

URL: CVE-2025-52999

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.634%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2025-06-25

Fix Resolution (com.fasterxml.jackson.core:jackson-core): 2.15.0

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.1.0

In order to enable automatic remediation, please create workflow rules

CVE-2024-38819

Vulnerable Library - spring-webmvc-5.3.21.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.21/spring-webmvc-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-webmvc-5.3.21.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.webwolf.MvcConfiguration (Application)
  -> org.springframework.web.servlet.config.annotation.ResourceHandlerRegistry (Extension)
   -> ❌ org.springframework.web.servlet.resource.ResourceHttpRequestHandler (Vulnerable Component)

Vulnerability Details

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

Publish Date: 2024-12-19

URL: CVE-2024-38819

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 54.862%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2024-38819

Release Date: 2024-12-19

Fix Resolution (org.springframework:spring-webmvc): 6.1.14

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.2.11

In order to enable automatic remediation, please create workflow rules

CVE-2024-38816

Vulnerable Library - spring-webmvc-5.3.21.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.21/spring-webmvc-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-webmvc-5.3.21.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.container.WebSecurityConfig (Application)
  -> org.springframework.security.config.annotation.web.configuration.WebSecurityConfiguration$1 (Extension)
   -> org.springframework.boot.autoconfigure.web.servlet.WebMvcAutoConfiguration$OptionalPathExtensionContentNegotiationStrategy (Extension)
    -> org.springframework.boot.autoconfigure.web.servlet.WebMvcAutoConfiguration (Extension)
    ...
      -> org.springframework.web.servlet.function.support.RouterFunctionMapping (Extension)
       -> org.springframework.web.servlet.function.RouterFunctions (Extension)
        -> ❌ org.springframework.web.servlet.function.PathResourceLookupFunction (Vulnerable Component)

Vulnerability Details

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.
Specifically, an application is vulnerable when both of the following are true:

  • the web application uses RouterFunctions to serve static resources
  • resource handling is explicitly configured with a FileSystemResource location
    However, malicious requests are blocked and rejected when any of the following is true:
  • the Spring Security HTTP Firewall https://docs.spring.io/spring-security/reference/servlet/exploits/firewall.html  is in use
  • the application runs on Tomcat or Jetty
    Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2024-09-13

URL: CVE-2024-38816

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 14.718%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2024-38816

Release Date: 2024-09-13

Fix Resolution (org.springframework:spring-webmvc): 6.1.13

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.2.10

In order to enable automatic remediation, please create workflow rules

CVE-2023-20860

Vulnerable Library - spring-webmvc-5.3.21.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.21/spring-webmvc-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-webmvc-5.3.21.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.webwolf.WebSecurityConfig (Application)
  -> org.springframework.security.config.annotation.web.configuration.WebSecurityConfiguration$1 (Extension)
   -> org.springframework.boot.autoconfigure.web.servlet.WebMvcAutoConfiguration$OptionalPathExtensionContentNegotiationStrategy (Extension)
    -> org.springframework.boot.autoconfigure.web.servlet.WebMvcAutoConfiguration (Extension)
    ...
      -> org.springframework.web.servlet.config.annotation.DelegatingWebMvcConfiguration (Extension)
       -> org.springframework.web.servlet.mvc.method.annotation.AbstractMessageConverterMethodProcessor (Extension)
        -> ❌ org.springframework.web.servlet.handler.PathPatternMatchableHandlerMapping (Vulnerable Component)

Vulnerability Details

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.

Publish Date: 2023-03-27

URL: CVE-2023-20860

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 3.514%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/blog/2023/03/21/this-week-in-spring-march-21st-2023/

Release Date: 2023-03-27

Fix Resolution (org.springframework:spring-webmvc): 5.3.26

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 2.7.10

In order to enable automatic remediation, please create workflow rules

CVE-2022-42004

Vulnerable Library - jackson-databind-2.13.3.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.13.3/jackson-databind-2.13.3.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-boot-starter-json-2.7.1.jar
      • jackson-databind-2.13.3.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.lessons.xss.stored.StoredXssComments (Application)
  -> com.fasterxml.jackson.databind.json.JsonMapper (Extension)
   -> ❌ com.fasterxml.jackson.databind.deser.std.EnumMapDeserializer (Vulnerable Component)

Vulnerability Details

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

Publish Date: 2022-10-02

URL: CVE-2022-42004

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 2.766%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2022-10-02

Fix Resolution (com.fasterxml.jackson.core:jackson-databind): 2.13.4

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 2.7.4

In order to enable automatic remediation, please create workflow rules

CVE-2022-42003

Vulnerable Library - jackson-databind-2.13.3.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.13.3/jackson-databind-2.13.3.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-boot-starter-json-2.7.1.jar
      • jackson-databind-2.13.3.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.lessons.csrf.CSRFFeedback (Application)
  -> com.fasterxml.jackson.databind.ObjectMapper (Extension)
   -> com.fasterxml.jackson.databind.introspect.BasicClassIntrospector (Extension)
    -> com.fasterxml.jackson.databind.introspect.AnnotatedClassResolver (Extension)
     -> ❌ com.fasterxml.jackson.databind.introspect.AnnotationCollector$OneCollector (Vulnerable Component)

Vulnerability Details

In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.

Publish Date: 2022-10-02

URL: CVE-2022-42003

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 2.766%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-jjjh-jjxp-wpff

Release Date: 2022-10-02

Fix Resolution (com.fasterxml.jackson.core:jackson-databind): 2.13.4.1

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 2.7.9

In order to enable automatic remediation, please create workflow rules

CVE-2026-22740

Vulnerable Library - spring-web-5.3.21.jar

Spring Web

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.21/spring-web-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-boot-starter-json-2.7.1.jar
      • spring-web-5.3.21.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.container.MvcConfiguration (Application)
  -> org.thymeleaf.extras.springsecurity5.dialect.SpringSecurityDialect (Extension)
   -> org.springframework.web.server.ServerWebExchange (Extension)
    -> org.springframework.http.codec.multipart.SynchronossPartHttpMessageReader$SynchronossFilePart (Extension)
     -> org.springframework.http.codec.multipart.SynchronossPartHttpMessageReader (Extension)
      -> ❌ org.springframework.http.codec.multipart.MultipartHttpMessageReader (Vulnerable Component)

Vulnerability Details

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space.
Older, unsupported versions are also affected.

Publish Date: 2026-04-29

URL: CVE-2026-22740

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.344%

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2026-22740

Release Date: 2026-04-18

Fix Resolution: org.springframework:spring-web:6.2.18,https://github.com/spring-projects/spring-framework.git - v7.0.7,org.springframework:spring-web:7.0.7,https://github.com/spring-projects/spring-framework.git - v6.2.18

CVE-2026-22737

Vulnerable Library - spring-webmvc-5.3.21.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.21/spring-webmvc-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-webmvc-5.3.21.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.webwolf.MvcConfiguration (Application)
  -> org.springframework.web.servlet.config.annotation.ResourceHandlerRegistry (Extension)
   -> org.springframework.web.servlet.resource.ResourceHttpRequestHandler (Extension)
    -> org.springframework.web.servlet.resource.PathResourceResolver (Extension)
     -> ❌ org.springframework.web.servlet.resource.AbstractResourceResolver (Vulnerable Component)

Vulnerability Details

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

Publish Date: 2026-03-19

URL: CVE-2026-22737

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.385%

CVSS 3 Score Details (5.9)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2026-22737

Release Date: 2026-03-19

Fix Resolution: org.springframework:spring-webflux:6.2.17,org.springframework:spring-webflux:7.0.6,https://github.com/spring-projects/spring-framework.git - v7.0.6

CVE-2025-41242

Vulnerable Library - spring-webmvc-5.3.21.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.21/spring-webmvc-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-webmvc-5.3.21.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.container.WebSecurityConfig (Application)
  -> org.springframework.security.config.annotation.web.configuration.WebSecurityConfiguration$1 (Extension)
   -> org.springframework.boot.autoconfigure.web.servlet.WebMvcAutoConfiguration$OptionalPathExtensionContentNegotiationStrategy (Extension)
    -> org.springframework.boot.autoconfigure.web.servlet.WebMvcAutoConfiguration (Extension)
     -> org.springframework.boot.autoconfigure.web.servlet.WebMvcAutoConfiguration$EnableWebMvcConfiguration (Extension)
      -> org.springframework.web.servlet.mvc.method.annotation.ExceptionHandlerExceptionResolver (Extension)
       -> ❌ org.springframework.web.servlet.view.json.AbstractJackson2View (Vulnerable Component)

Vulnerability Details

Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container.
An application can be vulnerable when all the following are true:

Publish Date: 2025-08-18

URL: CVE-2025-41242

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 2.054%

CVSS 3 Score Details (5.9)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2025-08-18

Fix Resolution: https://github.com/spring-projects/spring-framework.git - v6.2.10,org.springframework:spring-beans:6.2.10

CVE-2026-22745

Vulnerable Library - spring-webmvc-5.3.21.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.21/spring-webmvc-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-webmvc-5.3.21.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.webwolf.MvcConfiguration (Application)
  -> org.springframework.web.servlet.config.annotation.ResourceHandlerRegistry (Extension)
   -> org.springframework.web.servlet.config.annotation.ResourceHandlerRegistration (Extension)
    -> org.springframework.web.servlet.config.annotation.ResourceChainRegistration (Extension)
     -> ❌ org.springframework.web.servlet.resource.CachingResourceResolver (Vulnerable Component)

Vulnerability Details

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources.
More precisely, an application can be vulnerable when all the following are true:

  • the application is using Spring MVC or Spring WebFlux
  • the application is serving static resources from the file system
  • the application is running on a Windows platform
    When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.

Publish Date: 2026-04-29

URL: CVE-2026-22745

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.341%

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-04-29

Fix Resolution (org.springframework:spring-webmvc): 6.2.18

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.5.14

In order to enable automatic remediation, please create workflow rules

CVE-2024-38828

Vulnerable Libraries - spring-webmvc-5.3.21.jar, spring-web-5.3.21.jar

spring-webmvc-5.3.21.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.21/spring-webmvc-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-webmvc-5.3.21.jar (Vulnerable Library)

spring-web-5.3.21.jar

Spring Web

Library home page: https://github.com/spring-projects/spring-framework

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.21/spring-web-5.3.21.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.7.1.jar (Root Library)
    • spring-boot-starter-json-2.7.1.jar
      • spring-web-5.3.21.jar (Vulnerable Library)

Found in base branch: main

Reachability Analysis

This vulnerability is potentially reachable

org.owasp.webgoat.lessons.webwolfintroduction.LandingAssignment (Application)
  -> ❌ org.springframework.web.servlet.ModelAndView (Vulnerable Component)

Vulnerability Details

Spring MVC controller methods with an @⁠RequestBody byte[] method parameter are vulnerable to a DoS attack.

Publish Date: 2024-11-18

URL: CVE-2024-38828

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.729%

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.


In order to enable automatic remediation for this issue, please create workflow rules

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions