Skip to content

fix(deps): update dependency org.springframework.boot:spring-boot-starter-parent to v2.7.18 (wip) - autoclosed - #12

Closed
mend-for-github-com[bot] wants to merge 1 commit into
wipfrom
whitesource-remediate/wip-spring-boot
Closed

fix(deps): update dependency org.springframework.boot:spring-boot-starter-parent to v2.7.18 (wip) - autoclosed#12
mend-for-github-com[bot] wants to merge 1 commit into
wipfrom
whitesource-remediate/wip-spring-boot

fix(deps): update dependency org.springframework.boot:spring-boot-sta…

d85e5e3
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Apr 30, 2026 in 2m 35s

Security Report

You have successfully remediated 63 vulnerabilities, but introduced 52 new vulnerabilities in this branch.

❌ New vulnerabilities:

VulnerabilitySeverity CVSS ScoreExploit MaturityEPSSVulnerable LibraryDirect LibrarySuggested FixIssueReachability
CVE-2022-1471

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/yaml/snakeyaml/1.30/snakeyaml-1.30.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ snakeyaml-1.30.jar (Vulnerable Library)

High8.3Functional94.088%Transitive snakeyaml-1.30.jarspring-boot-starter-web-2.7.18.jarTransitive 2.0None

Reachable

CVE-2024-22262

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> ❌ spring-web-5.3.31.jar (Vulnerable Library)

High8.1Not Defined12.634%Transitive spring-web-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive 5.3.34None

Reachable

CVE-2024-22259

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> ❌ spring-web-5.3.31.jar (Vulnerable Library)

High8.1Not Defined56.395%Transitive spring-web-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive 5.3.33None

Reachable

CVE-2024-22243

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> ❌ spring-web-5.3.31.jar (Vulnerable Library)

High8.1Not Defined59.593%Transitive spring-web-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive 5.3.32None

Reachable

WS-2026-0003

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.5/jackson-core-2.13.5.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> jackson-databind-2.13.5.jar

-> ❌ jackson-core-2.13.5.jar (Vulnerable Library)

High7.5Not DefinedTransitive jackson-core-2.13.5.jarspring-boot-starter-web-2.7.18.jarTransitive 2.18.6None

Reachable

WS-2022-0468

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.5/jackson-core-2.13.5.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> jackson-databind-2.13.5.jar

-> ❌ jackson-core-2.13.5.jar (Vulnerable Library)

High7.5Not DefinedTransitive jackson-core-2.13.5.jarspring-boot-starter-web-2.7.18.jarTransitive 2.15.0-rc1None

Reachable

CVE-2025-52999

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.13.5/jackson-core-2.13.5.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> jackson-databind-2.13.5.jar

-> ❌ jackson-core-2.13.5.jar (Vulnerable Library)

High7.5Not Defined0.252%Transitive jackson-core-2.13.5.jarspring-boot-starter-web-2.7.18.jarTransitive 2.15.0None

Reachable

CVE-2025-41249

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.3.31/spring-core-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-2.7.18.jar

-> ❌ spring-core-5.3.31.jar (Vulnerable Library)

High7.5Not Defined0.069%Transitive spring-core-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitivehttps://github.com/spring-projects/spring-framework.git - v6.2.11,org.springframework:spring-core:6.2.11None

Reachable

CVE-2022-25857

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/yaml/snakeyaml/1.30/snakeyaml-1.30.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ snakeyaml-1.30.jar (Vulnerable Library)

High7.5Not Defined0.869%Transitive snakeyaml-1.30.jarspring-boot-starter-web-2.7.18.jarTransitive 1.31None

Reachable

CVE-2025-22235

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot/2.7.18/spring-boot-2.7.18.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ spring-boot-2.7.18.jar (Vulnerable Library)

High7.3Functional0.39%Transitive spring-boot-2.7.18.jarspring-boot-starter-web-2.7.18.jarTransitivehttps://github.com/spring-projects/spring-boot.git - v3.4.5,https://github.com/spring-projects/spring-boot.git - v3.3.11,org.springframework.boot:spring-boot-actuator-autoconfigure:3.4.5,org.springframework.boot:spring-boot-actuator-autoconfigure:3.3.11None

Reachable

CVE-2024-12798

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-classic/1.2.12/logback-classic-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-starter-logging-2.7.18.jar

-> ❌ logback-classic-1.2.12.jar (Vulnerable Library)

High7.3Not Defined0.124%Transitive logback-classic-1.2.12.jarspring-boot-starter-web-2.7.18.jarTransitive 1.3.15None

Reachable

CVE-2024-12798

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-starter-logging-2.7.18.jar

-> logback-classic-1.2.12.jar

-> ❌ logback-core-1.2.12.jar (Vulnerable Library)

High7.3Not Defined0.124%Transitive logback-core-1.2.12.jarspring-boot-starter-web-2.7.18.jarTransitive 1.3.15None

Reachable

CVE-2023-6481

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-starter-logging-2.7.18.jar

-> logback-classic-1.2.12.jar

-> ❌ logback-core-1.2.12.jar (Vulnerable Library)

High7.1Not Defined0.224%Transitive logback-core-1.2.12.jarspring-boot-starter-web-2.7.18.jarTransitive 1.2.13None

Reachable

CVE-2023-6378

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-classic/1.2.12/logback-classic-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-starter-logging-2.7.18.jar

-> ❌ logback-classic-1.2.12.jar (Vulnerable Library)

High7.1Not Defined0.613%Transitive logback-classic-1.2.12.jarspring-boot-starter-web-2.7.18.jarTransitive ch.qos.logback:logback-classic:1.3.12,1.4.12None

Reachable

CVE-2023-6378

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-starter-logging-2.7.18.jar

-> logback-classic-1.2.12.jar

-> ❌ logback-core-1.2.12.jar (Vulnerable Library)

High7.1Not Defined0.613%Transitive logback-core-1.2.12.jarspring-boot-starter-web-2.7.18.jarTransitive ch.qos.logback:logback-classic:1.3.12,1.4.12None

Reachable

CVE-2026-40973

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot/2.7.18/spring-boot-2.7.18.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ spring-boot-2.7.18.jar (Vulnerable Library)

High7.0Not Defined0.014%Transitive spring-boot-2.7.18.jarspring-boot-starter-web-2.7.18.jarTransitive 2.7.33None

Reachable

CVE-2026-22740

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> ❌ spring-web-5.3.31.jar (Vulnerable Library)

Medium6.5Not Defined0.033%Transitive spring-web-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive org.springframework:spring-web:6.2.18,https://github.com/spring-projects/spring-framework.git - v7.0.7,org.springframework:spring-web:7.0.7,https://github.com/spring-projects/spring-framework.git - v6.2.18None

Reachable

CVE-2022-38752

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/yaml/snakeyaml/1.30/snakeyaml-1.30.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ snakeyaml-1.30.jar (Vulnerable Library)

Medium6.5Not Defined0.205%Transitive snakeyaml-1.30.jarspring-boot-starter-web-2.7.18.jarTransitive 1.32None

Reachable

CVE-2022-38751

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/yaml/snakeyaml/1.30/snakeyaml-1.30.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ snakeyaml-1.30.jar (Vulnerable Library)

Medium6.5Not Defined0.21%Transitive snakeyaml-1.30.jarspring-boot-starter-web-2.7.18.jarTransitive 1.31None

Reachable

CVE-2022-38750

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/yaml/snakeyaml/1.30/snakeyaml-1.30.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ snakeyaml-1.30.jar (Vulnerable Library)

Medium6.5Not Defined0.221%Transitive snakeyaml-1.30.jarspring-boot-starter-web-2.7.18.jarTransitive 1.31None

Reachable

CVE-2022-38749

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/yaml/snakeyaml/1.30/snakeyaml-1.30.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ snakeyaml-1.30.jar (Vulnerable Library)

Medium6.5Not Defined0.533%Transitive snakeyaml-1.30.jarspring-boot-starter-web-2.7.18.jarTransitive 1.31None

Reachable

CVE-2026-22737

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

Medium5.9Not Defined0.092%Transitive spring-webmvc-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive org.springframework:spring-webflux:6.2.17,org.springframework:spring-webflux:7.0.6,https://github.com/spring-projects/spring-framework.git - v7.0.6None

Reachable

CVE-2025-41242

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

Medium5.9Not Defined0.087%Transitive spring-webmvc-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitivehttps://github.com/spring-projects/spring-framework.git - v6.2.10,org.springframework:spring-beans:6.2.10None

Reachable

CVE-2025-41242

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-beans/5.3.31/spring-beans-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-2.7.18.jar

-> spring-context-5.3.31.jar

-> spring-aop-5.3.31.jar

-> ❌ spring-beans-5.3.31.jar (Vulnerable Library)

Medium5.9Not Defined0.087%Transitive spring-beans-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitivehttps://github.com/spring-projects/spring-framework.git - v6.2.10,org.springframework:spring-beans:6.2.10None

Reachable

CVE-2022-41854

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/yaml/snakeyaml/1.30/snakeyaml-1.30.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ snakeyaml-1.30.jar (Vulnerable Library)

Medium5.8Not Defined0.116%Transitive snakeyaml-1.30.jarspring-boot-starter-web-2.7.18.jarTransitive 1.32None

Reachable

CVE-2024-38828

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> ❌ spring-web-5.3.31.jar (Vulnerable Library)

Medium5.3Not Defined0.076%Transitive spring-web-5.3.31.jarspring-boot-starter-web-2.7.18.jarNone

Reachable

CVE-2024-38828

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

Medium5.3Not Defined0.076%Transitive spring-webmvc-5.3.31.jarspring-boot-starter-web-2.7.18.jarNone

Reachable

CVE-2024-38828

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.3.31/spring-core-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-2.7.18.jar

-> ❌ spring-core-5.3.31.jar (Vulnerable Library)

Medium5.3Not Defined0.076%Transitive spring-core-5.3.31.jarspring-boot-starter-web-2.7.18.jarNone

Reachable

CVE-2024-38809

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> ❌ spring-web-5.3.31.jar (Vulnerable Library)

Medium5.3Not Defined0.14%Transitive spring-web-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive 5.3.38None

Reachable

CVE-2026-40974

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.7.18/spring-boot-autoconfigure-2.7.18.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ spring-boot-autoconfigure-2.7.18.jar (Vulnerable Library)

Medium5.0Not Defined0.014%Transitive spring-boot-autoconfigure-2.7.18.jarspring-boot-starter-web-2.7.18.jarTransitive 2.7.33None

Reachable

CVE-2026-1225

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-starter-logging-2.7.18.jar

-> logback-classic-1.2.12.jar

-> ❌ logback-core-1.2.12.jar (Vulnerable Library)

Medium5.0Not Defined0.012%Transitive logback-core-1.2.12.jarspring-boot-starter-web-2.7.18.jarTransitivehttps://github.com/qos-ch/logback.git - v_1.5.25None

Reachable

CVE-2026-40975

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot/2.7.18/spring-boot-2.7.18.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ spring-boot-2.7.18.jar (Vulnerable Library)

Medium4.8Not Defined0.028%Transitive spring-boot-2.7.18.jarspring-boot-starter-web-2.7.18.jarTransitive 2.7.33None

Reachable

CVE-2026-40977

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot/2.7.18/spring-boot-2.7.18.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> ❌ spring-boot-2.7.18.jar (Vulnerable Library)

Medium4.7Not Defined0.012%Transitive spring-boot-2.7.18.jarspring-boot-starter-web-2.7.18.jarTransitive 2.7.33None

Reachable

CVE-2024-12801

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-starter-logging-2.7.18.jar

-> logback-classic-1.2.12.jar

-> ❌ logback-core-1.2.12.jar (Vulnerable Library)

Medium4.6Not Defined0.047%Transitive logback-core-1.2.12.jarspring-boot-starter-web-2.7.18.jarTransitive 1.3.15None

Reachable

CVE-2024-38808

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/5.3.31/spring-expression-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-2.7.18.jar

-> spring-context-5.3.31.jar

-> ❌ spring-expression-5.3.31.jar (Vulnerable Library)

Medium4.3Not Defined0.809%Transitive spring-expression-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive 5.3.39None

Reachable

CVE-2025-22233

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-context/5.3.31/spring-context-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-2.7.18.jar

-> ❌ spring-context-5.3.31.jar (Vulnerable Library)

Low3.1Not Defined0.083%Transitive spring-context-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitivehttps://github.com/spring-projects/spring-framework.git - v6.1.20 ,org.springframework:spring-context:6.1.20,org.springframework:spring-context:6.2.7,https://github.com/spring-projects/spring-framework.git - v6.2.7None

Reachable

CVE-2024-38820

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/5.3.31/spring-core-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-2.7.18.jar

-> ❌ spring-core-5.3.31.jar (Vulnerable Library)

Low3.1Not Defined1.514%Transitive spring-core-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive org.springframework:spring-context:6.1.14None

Reachable

CVE-2024-38820

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> ❌ spring-web-5.3.31.jar (Vulnerable Library)

Low3.1Not Defined1.514%Transitive spring-web-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive org.springframework:spring-context:6.1.14None

Reachable

CVE-2024-38820

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-context/5.3.31/spring-context-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-2.7.18.jar

-> ❌ spring-context-5.3.31.jar (Vulnerable Library)

Low3.1Not Defined1.514%Transitive spring-context-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive org.springframework:spring-context:6.1.14None

Reachable

CVE-2024-38820

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

Low3.1Not Defined1.514%Transitive spring-webmvc-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive org.springframework:spring-context:6.1.14None

Reachable

CVE-2026-22735

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> ❌ spring-web-5.3.31.jar (Vulnerable Library)

Low2.6Not Defined0.092%Transitive spring-web-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive org.springframework:spring-webmvc:7.0.6,https://github.com/spring-projects/spring-framework.git - v7.0.6,https://github.com/spring-projects/spring-framework.git - v6.1.21,org.springframework:spring-web:7.0.6,org.springframework:spring-web:6.2.17,org.springframework:spring-webmvc:6.2.17,https://github.com/spring-projects/spring-framework.git - v6.2.17None

Reachable

CVE-2026-22735

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

Low2.6Not Defined0.092%Transitive spring-webmvc-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive org.springframework:spring-webmvc:7.0.6,https://github.com/spring-projects/spring-framework.git - v7.0.6,https://github.com/spring-projects/spring-framework.git - v6.1.21,org.springframework:spring-web:7.0.6,org.springframework:spring-web:6.2.17,org.springframework:spring-webmvc:6.2.17,https://github.com/spring-projects/spring-framework.git - v6.2.17None

Reachable

CVE-2016-1000027

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/5.3.31/spring-web-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-json-2.7.18.jar

-> ❌ spring-web-5.3.31.jar (Vulnerable Library)

Critical9.8Not Defined60.417%Transitive spring-web-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive 6.0.0None

Unreachable

CVE-2026-40478

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/thymeleaf/thymeleaf-spring5/3.0.15.RELEASE/thymeleaf-spring5-3.0.15.RELEASE.jar

Dependency Hierarchy:

-> spring-boot-starter-thymeleaf-2.7.18.jar (Root Library)

-> ❌ thymeleaf-spring5-3.0.15.RELEASE.jar (Vulnerable Library)

Critical9.0Not Defined0.051%Transitive thymeleaf-spring5-3.0.15.RELEASE.jarspring-boot-starter-thymeleaf-2.7.18.jarTransitive 3.1.4.RELEASENone

Unreachable

CVE-2026-40478

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/thymeleaf/thymeleaf/3.0.15.RELEASE/thymeleaf-3.0.15.RELEASE.jar

Dependency Hierarchy:

-> spring-boot-starter-thymeleaf-2.7.18.jar (Root Library)

-> thymeleaf-spring5-3.0.15.RELEASE.jar

-> ❌ thymeleaf-3.0.15.RELEASE.jar (Vulnerable Library)

Critical9.0Not Defined0.051%Transitive thymeleaf-3.0.15.RELEASE.jarspring-boot-starter-thymeleaf-2.7.18.jarTransitive 3.1.4.RELEASENone

Unreachable

CVE-2026-40477

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/thymeleaf/thymeleaf/3.0.15.RELEASE/thymeleaf-3.0.15.RELEASE.jar

Dependency Hierarchy:

-> spring-boot-starter-thymeleaf-2.7.18.jar (Root Library)

-> thymeleaf-spring5-3.0.15.RELEASE.jar

-> ❌ thymeleaf-3.0.15.RELEASE.jar (Vulnerable Library)

Critical9.0Not Defined0.051%Transitive thymeleaf-3.0.15.RELEASE.jarspring-boot-starter-thymeleaf-2.7.18.jarTransitive 3.1.4.RELEASENone

Unreachable

CVE-2026-40477

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/thymeleaf/thymeleaf-spring5/3.0.15.RELEASE/thymeleaf-spring5-3.0.15.RELEASE.jar

Dependency Hierarchy:

-> spring-boot-starter-thymeleaf-2.7.18.jar (Root Library)

-> ❌ thymeleaf-spring5-3.0.15.RELEASE.jar (Vulnerable Library)

Critical9.0Not Defined0.051%Transitive thymeleaf-spring5-3.0.15.RELEASE.jarspring-boot-starter-thymeleaf-2.7.18.jarTransitive 3.1.4.RELEASENone

Unreachable

CVE-2024-38819

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

High7.5Not Defined92.565%Transitive spring-webmvc-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive 6.1.14None

Unreachable

CVE-2024-38816

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

High7.5Not Defined93.877%Transitive spring-webmvc-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive 6.1.13None

Unreachable

CVE-2023-38286

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/thymeleaf/thymeleaf/3.0.15.RELEASE/thymeleaf-3.0.15.RELEASE.jar

Dependency Hierarchy:

-> spring-boot-starter-thymeleaf-2.7.18.jar (Root Library)

-> thymeleaf-spring5-3.0.15.RELEASE.jar

-> ❌ thymeleaf-3.0.15.RELEASE.jar (Vulnerable Library)

High7.5Not Defined0.145%Transitive thymeleaf-3.0.15.RELEASE.jarspring-boot-starter-thymeleaf-2.7.18.jarTransitive 3.1.2.RELEASENone

Unreachable

CVE-2025-11226

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/ch/qos/logback/logback-core/1.2.12/logback-core-1.2.12.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> spring-boot-starter-2.7.18.jar

-> spring-boot-starter-logging-2.7.18.jar

-> logback-classic-1.2.12.jar

-> ❌ logback-core-1.2.12.jar (Vulnerable Library)

Medium6.9Not Defined0.062%Transitive logback-core-1.2.12.jarspring-boot-starter-web-2.7.18.jarTransitive 1.3.16None

Unreachable

CVE-2026-22741

Path to dependency file: /test-app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/5.3.31/spring-webmvc-5.3.31.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.7.18.jar (Root Library)

-> ❌ spring-webmvc-5.3.31.jar (Vulnerable Library)

Low3.1Not Defined0.055%Transitive spring-webmvc-5.3.31.jarspring-boot-starter-web-2.7.18.jarTransitive org.springframework:spring-webmvc:7.0.7,org.springframework:spring-webmvc:6.2.18,https://github.com/spring-projects/spring-framework.git - v7.0.7,org.springframework:spring-webflux:6.2.18,org.springframework:spring-webflux:7.0.7,https://github.com/spring-projects/spring-framework.git - v6.2.18None

Unreachable

✔️ Remediated vulnerabilities:

VulnerabilityVulnerable Library
CVE-2023-20861spring-expression-5.2.10.RELEASE.jar
CVE-2022-22950spring-expression-5.2.10.RELEASE.jar
CVE-2025-11226logback-core-1.2.3.jar
CVE-2020-36518jackson-databind-2.11.3.jar
CVE-2022-38750snakeyaml-1.26.jar
CVE-2022-41854snakeyaml-1.26.jar
CVE-2026-40477thymeleaf-spring5-3.0.11.RELEASE.jar
CVE-2022-38752snakeyaml-1.26.jar
CVE-2025-22235spring-boot-2.3.5.RELEASE.jar
CVE-2024-22259spring-web-5.2.10.RELEASE.jar
CVE-2022-22970spring-beans-5.2.10.RELEASE.jar
CVE-2023-6378logback-classic-1.2.3.jar
CVE-2021-22096spring-webmvc-5.2.10.RELEASE.jar
CVE-2022-22965spring-webmvc-5.2.10.RELEASE.jar
CVE-2021-42550logback-classic-1.2.3.jar
CVE-2021-46877jackson-databind-2.11.3.jar
CVE-2024-38820spring-context-5.2.10.RELEASE.jar
CVE-2025-52999jackson-core-2.11.3.jar
CVE-2026-22735spring-webmvc-5.2.10.RELEASE.jar
CVE-2026-40477thymeleaf-3.0.11.RELEASE.jar
CVE-2026-1225logback-core-1.2.3.jar
WS-2022-0468jackson-core-2.11.3.jar
CVE-2021-42550logback-core-1.2.3.jar
CVE-2023-6378logback-core-1.2.3.jar
CVE-2025-49128jackson-core-2.11.3.jar
CVE-2024-12798logback-classic-1.2.3.jar
CVE-2023-6481logback-core-1.2.3.jar
CVE-2026-40478thymeleaf-spring5-3.0.11.RELEASE.jar
CVE-2016-1000027spring-web-5.2.10.RELEASE.jar
CVE-2024-38808spring-expression-5.2.10.RELEASE.jar
CVE-2024-38809spring-web-5.2.10.RELEASE.jar
CVE-2023-20863spring-expression-5.2.10.RELEASE.jar
CVE-2024-38820spring-web-5.2.10.RELEASE.jar
CVE-2021-22060spring-web-5.2.10.RELEASE.jar
CVE-2024-38828spring-webmvc-5.2.10.RELEASE.jar
CVE-2022-22965spring-beans-5.2.10.RELEASE.jar
CVE-2025-41249spring-core-5.2.10.RELEASE.jar
WS-2021-0616jackson-core-2.11.3.jar
CVE-2026-22735spring-web-5.2.10.RELEASE.jar
CVE-2022-38751snakeyaml-1.26.jar
CVE-2025-41242spring-beans-5.2.10.RELEASE.jar
CVE-2024-22262spring-web-5.2.10.RELEASE.jar
WS-2026-0003jackson-core-2.11.3.jar
CVE-2022-22968spring-context-5.2.10.RELEASE.jar
CVE-2024-38819spring-webmvc-5.2.10.RELEASE.jar
CVE-2022-38749snakeyaml-1.26.jar
CVE-2024-38816spring-webmvc-5.2.10.RELEASE.jar
CVE-2024-22243spring-web-5.2.10.RELEASE.jar
CVE-2022-42004jackson-databind-2.11.3.jar
CVE-2024-12798logback-core-1.2.3.jar
CVE-2022-25857snakeyaml-1.26.jar
CVE-2021-43466thymeleaf-spring5-3.0.11.RELEASE.jar
CVE-2021-22096spring-web-5.2.10.RELEASE.jar
CVE-2023-38286thymeleaf-3.0.11.RELEASE.jar
CVE-2022-22970spring-core-5.2.10.RELEASE.jar
CVE-2026-40478thymeleaf-3.0.11.RELEASE.jar
CVE-2022-42003jackson-databind-2.11.3.jar
WS-2021-0616jackson-databind-2.11.3.jar
CVE-2022-1471snakeyaml-1.26.jar
CVE-2024-12801logback-core-1.2.3.jar
CVE-2023-20883spring-boot-autoconfigure-2.3.5.RELEASE.jar
CVE-2025-22233spring-context-5.2.10.RELEASE.jar
CVE-2022-22965spring-boot-starter-web-2.3.5.RELEASE.jar

Base branch total remaining vulnerabilities: 63
Base branch commit: 302c67d57ff33993b59b4e4a0302421181d2e09c


Total libraries scanned: 34

Scan token: 6e20bec8c6674f2883db9454555f9876