Skip to content

fix(security): upgrade spring-boot-starter-web to 3.5.12 to resolve 4 vulnerabilities#11

Open
chore-bot[bot] wants to merge 1 commit intomasterfrom
snyk/b6261905-5698-42b1-9393-952f98d62459
Open

fix(security): upgrade spring-boot-starter-web to 3.5.12 to resolve 4 vulnerabilities#11
chore-bot[bot] wants to merge 1 commit intomasterfrom
snyk/b6261905-5698-42b1-9393-952f98d62459

Conversation

@chore-bot
Copy link
Copy Markdown
Contributor

@chore-bot chore-bot bot commented Mar 23, 2026

Upgraded org.springframework.boot:spring-boot-starter-web from 3.5.11 to 3.5.12 to resolve 4 vulnerabilities across spring-webmvc, spring-web, and jackson-core.

Vulnerabilities Fixed

  • SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924 in com.fasterxml.jackson.core:jackson-core 2.19.4 (HIGH)
  • SNYK-JAVA-ORGSPRINGFRAMEWORK-15701845 in org.springframework:spring-webmvc 6.2.16 (HIGH)
  • SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755 in org.springframework:spring-web 6.2.16 (LOW)
  • SNYK-JAVA-ORGSPRINGFRAMEWORK-15701756 in org.springframework:spring-webmvc 6.2.16 (LOW)

Changes

  • org.springframework.boot:spring-boot-starter-web: 3.5.11 → 3.5.12 (build.gradle)

Reasoning

Snyk recommended upgrading to 4.0.0 as the ideal fix, but that version failed validation. 3.5.12 is the lowest version that resolves all 4 vulnerabilities by pulling in spring-web@6.2.17, spring-webmvc@6.2.17, and a safe jackson-core version.

@snyk-github-integration
Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@chore-bot chore-bot bot marked this pull request as ready for review March 23, 2026 09:42
@chore-bot chore-bot bot enabled auto-merge (squash) March 23, 2026 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants