Skip to content

spring-boot-starter-web-2.3.5.RELEASE.jar: 72 vulnerabilities (highest severity is: 9.8) reachable #8

Description

@mend-for-github-com
Vulnerable Library - spring-boot-starter-web-2.3.5.RELEASE.jar

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.2.10.RELEASE/spring-expression-5.2.10.RELEASE.jar

Found in HEAD commit: 752b0398c84df02225991564ab382dbb91571883

Vulnerabilities

VulnerabilitySeverity CVSSExploit MaturityEPSSDependencyTypeFixed in (spring-boot-starter-web version)Remediation Possible**Reachability
CVE-2022-22965 Critical9.8High99.677%detected in multiple dependenciesTransitive2.4.0

Reachable

CVE-2022-1471 High8.3Functional99.569%snakeyaml-1.26.jarTransitive3.2.0

Reachable

CVE-2024-22262 High8.1Not Defined1.191%spring-web-5.2.10.RELEASE.jarTransitive3.0.0

Reachable

CVE-2024-22259 High8.1Not Defined2.573%spring-web-5.2.10.RELEASE.jarTransitive3.0.0

Reachable

CVE-2024-22243 High8.1Not Defined3.967%spring-web-5.2.10.RELEASE.jarTransitive3.0.0

Reachable

WS-2026-0003 High7.5Not Definedjackson-core-2.11.3.jarTransitive3.5.0

Reachable

WS-2022-0468 High7.5Not Definedjackson-core-2.11.3.jarTransitive3.1.0

Reachable

CVE-2025-52999 High7.5Not Defined0.665%jackson-core-2.11.3.jarTransitive3.1.0

Reachable

CVE-2025-41249 High7.5Not Defined0.46%spring-core-5.2.10.RELEASE.jarTransitiveN/A*

Reachable

CVE-2022-42004 High7.5Not Defined2.766%jackson-databind-2.11.3.jarTransitive2.6.0

Reachable

CVE-2022-42003 High7.5Not Defined2.766%jackson-databind-2.11.3.jarTransitive2.6.0

Reachable

CVE-2022-25857 High7.5Not Defined2.202%snakeyaml-1.26.jarTransitive3.0.0

Reachable

CVE-2021-46877 High7.5Not Defined1.124%jackson-databind-2.11.3.jarTransitive2.5.8

Reachable

CVE-2020-36518 High7.5Not Defined4.86%jackson-databind-2.11.3.jarTransitiveN/A*

Reachable

CVE-2025-22235 High7.3Functional0.415%spring-boot-2.3.5.RELEASE.jarTransitiveN/A*

Reachable

CVE-2024-12798 High7.3Not Defined0.404%detected in multiple dependenciesTransitive4.0.0

Reachable

CVE-2023-6481 High7.1Not Defined0.682%logback-core-1.2.3.jarTransitiveN/A*

Reachable

CVE-2023-6378 High7.1Not Defined0.9%detected in multiple dependenciesTransitive3.2.1

Reachable

CVE-2021-42550 Medium6.6Not Defined4.439%detected in multiple dependenciesTransitive2.5.8

Reachable

CVE-2023-20863 Medium6.5Not Defined1.122%spring-expression-5.2.10.RELEASE.jarTransitive2.4.0

Reachable

CVE-2023-20861 Medium6.5Not Defined0.97%spring-expression-5.2.10.RELEASE.jarTransitive2.4.0

Reachable

CVE-2022-38752 Medium6.5Not Defined2.101%snakeyaml-1.26.jarTransitive3.0.0

Reachable

CVE-2022-38751 Medium6.5Not Defined1.515%snakeyaml-1.26.jarTransitive3.0.0

Reachable

CVE-2022-38750 Medium6.5Not Defined1.047%snakeyaml-1.26.jarTransitive3.0.0

Reachable

CVE-2022-38749 Medium6.5Not Defined1.65%snakeyaml-1.26.jarTransitive3.0.0

Reachable

CVE-2022-22950 Medium6.5Not Defined36.081%spring-expression-5.2.10.RELEASE.jarTransitive2.4.0

Reachable

WS-2021-0616 Medium5.9Not Defineddetected in multiple dependenciesTransitive2.5.8

Reachable

CVE-2025-41242 Medium5.9Not Defined2.054%spring-beans-5.2.10.RELEASE.jarTransitiveN/A*

Reachable

CVE-2022-41854 Medium5.8Not Defined1.476%snakeyaml-1.26.jarTransitive3.0.0

Reachable

CVE-2024-38828 Medium5.3Not Defined0.729%spring-webmvc-5.2.10.RELEASE.jarTransitiveN/A*

Reachable

CVE-2024-38809 Medium5.3Not Defined0.852%spring-web-5.2.10.RELEASE.jarTransitive3.0.0

Reachable

CVE-2022-22970 Medium5.3Not Defined1.962%detected in multiple dependenciesTransitive2.4.0

Reachable

CVE-2022-22968 Medium5.3Not Defined5.666%spring-context-5.2.10.RELEASE.jarTransitive2.4.0

Reachable

CVE-2026-1225 Medium5.0Not Defined0.159%logback-core-1.2.3.jarTransitiveN/A*

Reachable

CVE-2024-12801 Medium4.6Not Defined0.225%logback-core-1.2.3.jarTransitive4.0.0

Reachable

CVE-2024-38808 Medium4.3Not Defined0.568%spring-expression-5.2.10.RELEASE.jarTransitive3.0.0

Reachable

CVE-2021-22096 Medium4.3Not Defined1.268%detected in multiple dependenciesTransitive2.4.0

Reachable

CVE-2021-22060 Medium4.3Not Defined0.855%spring-web-5.2.10.RELEASE.jarTransitive2.4.0

Reachable

CVE-2025-49128 Medium4.0Not Defined0.339%jackson-core-2.11.3.jarTransitiveN/A*

Reachable

CVE-2025-22233 Low3.1Not Defined0.379%spring-context-5.2.10.RELEASE.jarTransitiveN/A*

Reachable

CVE-2024-38820 Low3.1Not Defined0.617%detected in multiple dependenciesTransitive3.2.11

Reachable

CVE-2026-22735 Low2.6Not Defined0.112%detected in multiple dependenciesTransitiveN/A*

Reachable

CVE-2016-1000027 Critical9.8Not Defined32.257%spring-web-5.2.10.RELEASE.jarTransitive2.4.0

Unreachable

CVE-2025-11226 High7.9Not Defined0.181%logback-core-1.2.3.jarTransitive4.0.0

Unreachable

CVE-2024-38819 High7.5Not Defined54.862%spring-webmvc-5.2.10.RELEASE.jarTransitive3.2.11

Unreachable

CVE-2024-38816 High7.5Not Defined14.718%spring-webmvc-5.2.10.RELEASE.jarTransitive3.2.10

Unreachable

CVE-2023-20883 High7.5Not Defined0.904%spring-boot-autoconfigure-2.3.5.RELEASE.jarTransitive2.5.15

Unreachable

CVE-2026-54513 High8.1Not Defined0.712%jackson-databind-2.11.3.jarTransitiveN/A*
CVE-2026-54512 High8.1Not Defined0.779%jackson-databind-2.11.3.jarTransitiveN/A*
CVE-2026-13006 High7.9Not Defined0.122%logback-core-1.2.3.jarTransitiveN/A*
CVE-2026-41850 High7.5Not Defined0.36%spring-expression-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-41849 High7.5Not Defined0.263%spring-expression-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-41842 High7.5Not Defined0.399%spring-webmvc-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-19880 High7.3Not Definedlogback-classic-1.2.3.jarTransitiveN/A*
CVE-2026-41845 High7.1Not Defined0.161%spring-webmvc-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-40973 High7.0Not Defined0.136%spring-boot-2.3.5.RELEASE.jarTransitiveN/A*
CVE-2026-41846 Medium5.9Not Defined0.14%spring-webmvc-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-41843 Medium5.9Not Defined0.341%spring-webmvc-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-41841 Medium5.9Not Defined0.313%spring-webmvc-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-49844 Medium5.8Not Defined0.574%log4j-api-2.13.3.jarTransitiveN/A*
CVE-2026-9828 Medium5.4Not Defined0.37%logback-core-1.2.3.jarTransitiveN/A*
CVE-2026-10532 Medium5.4Not Defined0.37%logback-core-1.2.3.jarTransitiveN/A*
CVE-2026-54515 Medium5.3Not Defined0.345%jackson-databind-2.11.3.jarTransitiveN/A*
CVE-2026-54514 Medium5.3Not Defined0.219%jackson-databind-2.11.3.jarTransitiveN/A*
CVE-2026-50193 Medium5.3Not Defined0.459%jackson-databind-2.11.3.jarTransitiveN/A*
CVE-2026-41853 Medium5.3Not Defined0.186%spring-webmvc-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-41851 Medium5.3Not Defined0.36%spring-expression-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-22745 Medium5.3Not Defined0.341%spring-webmvc-5.2.10.RELEASE.jarTransitive3.5.14
CVE-2026-41844 Medium4.2Not Defined0.134%spring-webmvc-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-41852 Low3.7Not Defined0.177%spring-expression-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-41848 Low3.7Not Defined0.317%spring-core-5.2.10.RELEASE.jarTransitiveN/A*
CVE-2026-22741 Low3.1Not Defined0.236%spring-webmvc-5.2.10.RELEASE.jarTransitiveN/A*

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

Partial details (10 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.

CVE-2022-22965

Vulnerable Libraries - spring-beans-5.2.10.RELEASE.jar, spring-boot-starter-web-2.3.5.RELEASE.jar

spring-beans-5.2.10.RELEASE.jar

Spring Beans

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-beans/5.2.10.RELEASE/spring-beans-5.2.10.RELEASE.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.3.5.RELEASE.jar (Root Library)
    • spring-boot-starter-2.3.5.RELEASE.jar
      • spring-boot-2.3.5.RELEASE.jar
        • spring-context-5.2.10.RELEASE.jar
          • spring-aop-5.2.10.RELEASE.jar
            • spring-beans-5.2.10.RELEASE.jar (Vulnerable Library)

spring-boot-starter-web-2.3.5.RELEASE.jar

Starter for building web, including RESTful, applications using Spring MVC. Uses Tomcat as the default embedded container

Library home page: https://spring.io

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-starter-web/2.3.5.RELEASE/spring-boot-starter-web-2.3.5.RELEASE.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.3.5.RELEASE.jar (Vulnerable Library)

Found in HEAD commit: 752b0398c84df02225991564ab382dbb91571883

Found in base branch: wip

Reachability Analysis

This vulnerability is potentially reachable

com.example.demo.HandlingFormSubmissionApplication (Application)
-> org.springframework.boot.SpringApplication (Extension)
-> ❌ org.springframework.beans.CachedIntrospectionResults (Vulnerable Component)

Vulnerability Details

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2022-04-01

URL: CVE-2022-22965

Threat Assessment

Exploit Maturity: High

EPSS: 99.677%

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement

Release Date: 2022-04-01

Fix Resolution (org.springframework:spring-beans): 5.2.20.RELEASE

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 2.4.0

⛑️ Automatic Remediation will be attempted for this issue.

CVE-2022-1471

Vulnerable Library - snakeyaml-1.26.jar

YAML 1.1 parser and emitter for Java

Library home page: http://www.snakeyaml.org

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/yaml/snakeyaml/1.26/snakeyaml-1.26.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.3.5.RELEASE.jar (Root Library)
    • spring-boot-starter-2.3.5.RELEASE.jar
      • snakeyaml-1.26.jar (Vulnerable Library)

Found in HEAD commit: 752b0398c84df02225991564ab382dbb91571883

Found in base branch: wip

Reachability Analysis

This vulnerability is potentially reachable

com.example.demo.HandlingFormSubmissionApplication (Application)
-> org.springframework.boot.SpringApplication (Extension)
-> org.springframework.beans.factory.support.DefaultListableBeanFactory (Extension)
-> org.springframework.beans.factory.config.YamlMapFactoryBean (Extension)
-> org.springframework.beans.factory.config.YamlProcessor (Extension)
-> ❌ org.yaml.snakeyaml.LoaderOptions (Vulnerable Component)

Vulnerability Details

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

Publish Date: 2022-12-01

URL: CVE-2022-1471

Threat Assessment

Exploit Maturity: Functional

EPSS: 99.569%

CVSS 3 Score Details (8.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64634374

Release Date: 2022-12-01

Fix Resolution (org.yaml:snakeyaml): 2.0

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.2.0

In order to enable automatic remediation, please create workflow rules

CVE-2024-22262

Vulnerable Library - spring-web-5.2.10.RELEASE.jar

Spring Web

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.2.10.RELEASE/spring-web-5.2.10.RELEASE.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.3.5.RELEASE.jar (Root Library)
    • spring-boot-starter-json-2.3.5.RELEASE.jar
      • spring-web-5.2.10.RELEASE.jar (Vulnerable Library)

Found in HEAD commit: 752b0398c84df02225991564ab382dbb91571883

Found in base branch: wip

Reachability Analysis

This vulnerability is potentially reachable

com.example.demo.HandlingFormSubmissionApplication (Application)
-> org.springframework.boot.SpringApplication (Extension)
-> org.springframework.beans.factory.support.DefaultListableBeanFactory (Extension)
-> org.springframework.web.servlet.mvc.method.annotation.ServletInvocableHandlerMethod$ConcurrentResultMethodParameter (Extension)
...
-> org.springframework.web.context.request.ServletWebRequest (Extension)
-> org.springframework.web.util.WebUtils (Extension)
-> ❌ org.springframework.web.util.UriComponentsBuilder (Vulnerable Component)

Vulnerability Details

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22259https://spring.io/security/cve-2024-22259 and CVE-2024-22243https://spring.io/security/cve-2024-22243 , but with different input.

Publish Date: 2024-04-16

URL: CVE-2024-22262

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 1.191%

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2024-22262

Release Date: 2024-04-16

Fix Resolution (org.springframework:spring-web): 5.3.34

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.0.0

In order to enable automatic remediation, please create workflow rules

CVE-2024-22259

Vulnerable Library - spring-web-5.2.10.RELEASE.jar

Spring Web

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.2.10.RELEASE/spring-web-5.2.10.RELEASE.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.3.5.RELEASE.jar (Root Library)
    • spring-boot-starter-json-2.3.5.RELEASE.jar
      • spring-web-5.2.10.RELEASE.jar (Vulnerable Library)

Found in HEAD commit: 752b0398c84df02225991564ab382dbb91571883

Found in base branch: wip

Reachability Analysis

This vulnerability is potentially reachable

com.example.demo.HandlingFormSubmissionApplication (Application)
-> org.springframework.boot.SpringApplication (Extension)
-> org.springframework.beans.factory.support.DefaultListableBeanFactory (Extension)
-> org.springframework.web.servlet.mvc.method.annotation.ServletInvocableHandlerMethod$ConcurrentResultMethodParameter (Extension)
...
-> org.springframework.web.context.request.ServletWebRequest (Extension)
-> org.springframework.web.util.WebUtils (Extension)
-> ❌ org.springframework.web.util.UriComponentsBuilder (Vulnerable Component)

Vulnerability Details

Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22243https://spring.io/security/cve-2024-22243 , but with different input.

Publish Date: 2024-03-16

URL: CVE-2024-22259

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 2.573%

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2024-22259

Release Date: 2024-03-16

Fix Resolution (org.springframework:spring-web): 5.3.33

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.0.0

In order to enable automatic remediation, please create workflow rules

CVE-2024-22243

Vulnerable Library - spring-web-5.2.10.RELEASE.jar

Spring Web

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.2.10.RELEASE/spring-web-5.2.10.RELEASE.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.3.5.RELEASE.jar (Root Library)
    • spring-boot-starter-json-2.3.5.RELEASE.jar
      • spring-web-5.2.10.RELEASE.jar (Vulnerable Library)

Found in HEAD commit: 752b0398c84df02225991564ab382dbb91571883

Found in base branch: wip

Reachability Analysis

This vulnerability is potentially reachable

com.example.demo.HandlingFormSubmissionApplication (Application)
-> org.springframework.boot.SpringApplication (Extension)
-> org.springframework.beans.factory.support.DefaultListableBeanFactory (Extension)
-> org.springframework.web.servlet.mvc.method.annotation.ServletInvocableHandlerMethod$ConcurrentResultMethodParameter (Extension)
...
-> org.springframework.web.context.request.ServletWebRequest (Extension)
-> org.springframework.web.util.WebUtils (Extension)
-> ❌ org.springframework.web.util.UriComponentsBuilder (Vulnerable Component)

Vulnerability Details

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.

Publish Date: 2024-02-23

URL: CVE-2024-22243

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 3.967%

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2024-22243

Release Date: 2024-02-23

Fix Resolution (org.springframework:spring-web): 5.3.32

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.0.0

In order to enable automatic remediation, please create workflow rules

WS-2026-0003

Vulnerable Library - jackson-core-2.11.3.jar

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

Library home page: http://fasterxml.com/

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.11.3/jackson-core-2.11.3.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.3.5.RELEASE.jar (Root Library)
    • spring-boot-starter-json-2.3.5.RELEASE.jar
      • jackson-databind-2.11.3.jar
        • jackson-core-2.11.3.jar (Vulnerable Library)

Found in HEAD commit: 752b0398c84df02225991564ab382dbb91571883

Found in base branch: wip

Reachability Analysis

This vulnerability is potentially reachable

com.example.demo.HandlingFormSubmissionApplication (Application)
-> org.springframework.boot.SpringApplication (Extension)
-> org.springframework.boot.context.ConfigurationWarningsApplicationContextInitializer (Extension)
-> org.springframework.web.filter.HttpPutFormContentFilter (Extension)
...
-> org.springframework.http.converter.smile.MappingJackson2SmileHttpMessageConverter (Extension)
-> com.fasterxml.jackson.core.JsonFactory (Extension)
-> ❌ com.fasterxml.jackson.core.format.MatchStrength (Vulnerable Component)

Vulnerability Details

The non-blocking (async) JSON parser in jackson-core bypasses the maxNumberLength constraint (default: 1000 characters) defined in StreamReadConstraints. This allows an attacker to send JSON with arbitrarily long numbers through the async parser API, leading to excessive memory allocation and potential CPU exhaustion, resulting in a Denial of Service (DoS).

The standard synchronous parser correctly enforces this limit, but the async parser fails to do so, creating an inconsistent enforcement policy.

Publish Date: 2026-03-02

URL: WS-2026-0003

Threat Assessment

Exploit Maturity: Not Defined

EPSS:

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-72hv-8253-57qq

Release Date: 2026-03-02

Fix Resolution (com.fasterxml.jackson.core:jackson-core): 2.18.6

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.5.0

In order to enable automatic remediation, please create workflow rules

WS-2022-0468

Vulnerable Library - jackson-core-2.11.3.jar

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

Library home page: http://fasterxml.com/

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.11.3/jackson-core-2.11.3.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.3.5.RELEASE.jar (Root Library)
    • spring-boot-starter-json-2.3.5.RELEASE.jar
      • jackson-databind-2.11.3.jar
        • jackson-core-2.11.3.jar (Vulnerable Library)

Found in HEAD commit: 752b0398c84df02225991564ab382dbb91571883

Found in base branch: wip

Reachability Analysis

This vulnerability is potentially reachable

com.example.demo.HandlingFormSubmissionApplication (Application)
-> org.springframework.boot.SpringApplication (Extension)
-> org.springframework.boot.env.SpringApplicationJsonEnvironmentPostProcessor$JsonPropertySource (Extension)
-> org.springframework.boot.json.JsonParserFactory (Extension)
...
-> com.fasterxml.jackson.databind.ObjectMapper (Extension)
-> com.fasterxml.jackson.core.io.SegmentedStringWriter (Extension)
-> ❌ com.fasterxml.jackson.core.util.TextBuffer (Vulnerable Component)

Vulnerability Details

The jackson-core package is vulnerable to a Denial of Service (DoS) attack. The methods in the classes listed below fail to restrict input size when performing numeric type conversions. A remote attacker can exploit this vulnerability by causing the application to deserialize data containing certain numeric types with large values. Deserializing many of the aforementioned objects may cause the application to exhaust all available resources, resulting in a DoS condition.

Publish Date: 2026-05-20

URL: WS-2022-0468

Threat Assessment

Exploit Maturity: Not Defined

EPSS:

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2022-12-07

Fix Resolution (com.fasterxml.jackson.core:jackson-core): 2.15.0-rc1

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.1.0

In order to enable automatic remediation, please create workflow rules

CVE-2025-52999

Vulnerable Library - jackson-core-2.11.3.jar

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

Library home page: http://fasterxml.com/

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.11.3/jackson-core-2.11.3.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.3.5.RELEASE.jar (Root Library)
    • spring-boot-starter-json-2.3.5.RELEASE.jar
      • jackson-databind-2.11.3.jar
        • jackson-core-2.11.3.jar (Vulnerable Library)

Found in HEAD commit: 752b0398c84df02225991564ab382dbb91571883

Found in base branch: wip

Reachability Analysis

This vulnerability is potentially reachable

com.example.demo.HandlingFormSubmissionApplication (Application)
-> org.springframework.boot.SpringApplication (Extension)
-> org.springframework.boot.web.servlet.context.ServletWebServerApplicationContext (Extension)
-> com.fasterxml.jackson.databind.ser.BeanPropertyFilter (Extension)
...
-> com.fasterxml.jackson.databind.ser.std.NumberSerializers$Base (Extension)
-> com.fasterxml.jackson.core.JsonParser (Extension)
-> ❌ com.fasterxml.jackson.core.json.JsonReadContext (Vulnerable Component)

Vulnerability Details

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.

Publish Date: 2025-06-25

URL: CVE-2025-52999

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.665%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2025-06-25

Fix Resolution (com.fasterxml.jackson.core:jackson-core): 2.15.0

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 3.1.0

In order to enable automatic remediation, please create workflow rules

CVE-2025-41249

Vulnerable Library - spring-core-5.2.10.RELEASE.jar

Spring Core

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.2.10.RELEASE/spring-core-5.2.10.RELEASE.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.3.5.RELEASE.jar (Root Library)
    • spring-boot-starter-2.3.5.RELEASE.jar
      • spring-boot-2.3.5.RELEASE.jar
        • spring-core-5.2.10.RELEASE.jar (Vulnerable Library)

Found in HEAD commit: 752b0398c84df02225991564ab382dbb91571883

Found in base branch: wip

Reachability Analysis

This vulnerability is potentially reachable

com.example.demo.HandlingFormSubmissionApplication (Application)
-> org.springframework.boot.SpringApplication (Extension)
-> org.springframework.context.annotation.AnnotationConfigUtils (Extension)
-> org.springframework.aop.scope.ScopedProxyFactoryBean (Extension)
...
-> org.springframework.aop.framework.CglibAopProxy$CglibMethodInvocation (Extension)
-> org.springframework.cglib.proxy.MethodProxy (Extension)
-> ❌ org.springframework.cglib.proxy.MethodProxy$FastClassInfo (Vulnerable Component)

Vulnerability Details

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.
Your application may be affected by this if you are using Spring Security's @⁠EnableMethodSecurity feature.
You are not affected by this if you are not using @⁠EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.
This CVE is published in conjunction with CVE-2025-41248https://spring.io/security/cve-2025-41248 .
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2025-09-16

URL: CVE-2025-41249

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.46%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2025-41249

Release Date: 2025-09-14

Fix Resolution: https://github.com/spring-projects/spring-framework.git - v6.2.11,org.springframework:spring-core:6.2.11

CVE-2022-42004

Vulnerable Library - jackson-databind-2.11.3.jar

General data-binding functionality for Jackson: works on core streaming API

Library home page: http://fasterxml.com/

Sample Path to Dependency File: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.11.3/jackson-databind-2.11.3.jar

Dependency Hierarchy:

  • spring-boot-starter-web-2.3.5.RELEASE.jar (Root Library)
    • spring-boot-starter-json-2.3.5.RELEASE.jar
      • jackson-databind-2.11.3.jar (Vulnerable Library)

Found in HEAD commit: 752b0398c84df02225991564ab382dbb91571883

Found in base branch: wip

Reachability Analysis

This vulnerability is potentially reachable

com.example.demo.HandlingFormSubmissionApplication (Application)
-> org.springframework.boot.web.servlet.support.SpringBootServletInitializer (Extension)
-> org.springframework.context.ConfigurableApplicationContext (Extension)
-> org.springframework.http.codec.support.BaseDefaultCodecs (Extension)
...
-> org.springframework.http.converter.json.Jackson2ObjectMapperBuilder (Extension)
-> com.fasterxml.jackson.databind.module.SimpleModule (Extension)
-> ❌ com.fasterxml.jackson.databind.deser.BeanDeserializer (Vulnerable Component)

Vulnerability Details

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

Publish Date: 2022-10-02

URL: CVE-2022-42004

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 2.766%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2022-10-02

Fix Resolution (com.fasterxml.jackson.core:jackson-databind): 2.12.7.1

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 2.6.0

In order to enable automatic remediation, please create workflow rules


⛑️Automatic Remediation will be attempted for this issue.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions