Skip to content

spring-boot-starter-web-4.0.4.jar: 74 vulnerabilities (highest severity is: 9.8) #71

Description

@mend-bolt-for-github
Vulnerable Library - spring-boot-starter-web-4.0.4.jar

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Vulnerabilities

VulnerabilitySeverity CVSSDependencyTypeFixed in (spring-boot-starter-web version)Remediation Possible**
CVE-2026-65905 Critical9.8tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-59313 Critical9.8spring-webmvc-7.0.6.jarTransitive4.0.8
CVE-2026-47891 Critical9.8spring-web-7.0.6.jarTransitive4.0.8
CVE-2026-47890 Critical9.8spring-webmvc-7.0.6.jarTransitive4.0.8
CVE-2026-47884 Critical9.8spring-webmvc-7.0.6.jarTransitive4.0.8
CVE-2026-43512 Critical9.8tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-41293 Critical9.8tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-68525 Critical9.1tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-65182 Critical9.1tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-59283 Critical9.1spring-expression-7.0.6.jarTransitive4.0.8
CVE-2026-59084 Critical9.1tomcat-embed-core-11.0.18.jarTransitive4.0.8
CVE-2026-59083 Critical9.1tomcat-embed-core-11.0.18.jarTransitive4.0.8
CVE-2026-43515 Critical9.1tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-40976 Critical9.1spring-boot-4.0.4.jarTransitiveN/A*
CVE-2026-29145 Critical9.1tomcat-embed-core-11.0.18.jarTransitive4.0.5
CVE-2026-68569 High8.1tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-66422 High8.1tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-65183 High8.1tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-54513 High8.1jackson-databind-3.1.0.jarTransitiveN/A*
CVE-2026-54512 High8.1jackson-databind-3.1.0.jarTransitiveN/A*
WS-2026-0010 High7.5jackson-core-3.1.0.jarTransitive4.0.6
CVE-2026-68763 High7.5tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-68494 High7.5jackson-core-3.1.0.jarTransitive4.0.7
CVE-2026-65927 High7.5tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-59282 High7.5spring-beans-7.0.6.jarTransitive4.0.8
CVE-2026-47889 High7.5spring-web-7.0.6.jarTransitive4.0.8
CVE-2026-47886 High7.5spring-expression-7.0.6.jarTransitive4.0.8
CVE-2026-47885 High7.5spring-web-7.0.6.jarTransitive4.0.8
CVE-2026-43513 High7.5tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-41850 High7.5spring-expression-7.0.6.jarTransitive4.0.7
CVE-2026-41842 High7.5spring-webmvc-7.0.6.jarTransitive4.0.7
CVE-2026-41284 High7.5tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-34487 High7.5tomcat-embed-core-11.0.18.jarTransitive4.0.6
CVE-2026-34483 High7.5tomcat-embed-core-11.0.18.jarTransitive4.0.6
CVE-2026-29146 High7.5tomcat-embed-core-11.0.18.jarTransitive4.0.5
CVE-2026-29129 High7.5tomcat-embed-core-11.0.18.jarTransitive4.0.5
CVE-2026-24880 High7.5tomcat-embed-core-11.0.18.jarTransitive4.0.5
CVE-2026-42498 High7.3tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-41845 High7.1detected in multiple dependenciesTransitiveN/A*
CVE-2026-40973 High7.0spring-boot-4.0.4.jarTransitive4.0.6
CVE-2026-73180 Medium6.8tomcat-embed-websocket-11.0.18.jarTransitiveN/A*
CVE-2026-59889 Medium6.5jackson-databind-3.1.0.jarTransitive4.0.8
CVE-2026-59888 Medium6.5jackson-databind-3.1.0.jarTransitive4.0.7
CVE-2026-54518 Medium6.5jackson-databind-3.1.0.jarTransitiveN/A*
CVE-2026-22740 Medium6.5spring-web-7.0.6.jarTransitive4.0.6
CVE-2026-59281 Medium6.1spring-web-7.0.6.jarTransitive4.0.8
CVE-2026-47887 Medium6.1spring-webmvc-7.0.6.jarTransitive4.0.8
CVE-2026-47883 Medium6.1spring-web-7.0.6.jarTransitive4.0.8
CVE-2026-25854 Medium6.1tomcat-embed-core-11.0.18.jarTransitive4.0.5
CVE-2026-41846 Medium5.9spring-webmvc-7.0.6.jarTransitive4.0.7
CVE-2026-41843 Medium5.9spring-webmvc-7.0.6.jarTransitive4.0.7
CVE-2026-41841 Medium5.9spring-webmvc-7.0.6.jarTransitive4.0.7
CVE-2026-41840 Medium5.9spring-web-7.0.6.jarTransitive4.0.7
CVE-2026-83557 Medium5.6jackson-databind-3.1.0.jarTransitiveN/A*
CVE-2026-77310 Medium5.3jackson-databind-3.1.0.jarTransitive4.0.8
CVE-2026-54517 Medium5.3jackson-databind-3.1.0.jarTransitiveN/A*
CVE-2026-54516 Medium5.3jackson-databind-3.1.0.jarTransitiveN/A*
CVE-2026-54515 Medium5.3jackson-databind-3.1.0.jarTransitiveN/A*
CVE-2026-54514 Medium5.3jackson-databind-3.1.0.jarTransitiveN/A*
CVE-2026-41853 Medium5.3detected in multiple dependenciesTransitive4.0.7
CVE-2026-41851 Medium5.3spring-expression-7.0.6.jarTransitive4.0.7
CVE-2026-32990 Medium5.3tomcat-embed-core-11.0.18.jarTransitive4.0.5
CVE-2026-22745 Medium5.3spring-webmvc-7.0.6.jarTransitiveN/A*
CVE-2026-19032 Medium5.3jackson-databind-3.1.0.jarTransitiveN/A*
CVE-2026-40975 Medium4.8spring-boot-4.0.4.jarTransitive4.0.6
CVE-2026-40977 Medium4.7spring-boot-4.0.4.jarTransitive4.0.6
CVE-2026-41854 Medium4.2spring-web-7.0.6.jarTransitive4.0.7
CVE-2026-41844 Medium4.2spring-webmvc-7.0.6.jarTransitive4.0.7
CVE-2026-41839 Medium4.2spring-web-7.0.6.jarTransitive4.0.7
CVE-2026-59314 Low3.7spring-web-7.0.6.jarTransitive4.0.8
CVE-2026-43514 Low3.7tomcat-embed-core-11.0.18.jarTransitiveN/A*
CVE-2026-41852 Low3.7spring-expression-7.0.6.jarTransitive4.0.7
CVE-2026-41848 Low3.7spring-core-7.0.6.jarTransitive4.0.7
CVE-2026-22741 Low3.1spring-webmvc-7.0.6.jarTransitive4.0.6

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

Partial details (16 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.

CVE-2026-65905

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while the
associated nonceCount remains within the replay window.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

Publish Date: 2026-08-25

URL: CVE-2026-65905

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,org.apache.tomcat:tomcat-catalina:10.1.59,https://github.com/apache/tomcat.git - 11.0.25,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,https://github.com/apache/tomcat.git - 9.0.121,https://github.com/apache/tomcat.git - 10.1.58

Step up your Open Source Security Game with Mend here

CVE-2026-59313

Vulnerable Library - spring-webmvc-7.0.6.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-webmvc-4.0.4.jar
      • spring-webmvc-7.0.6.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE).
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49

Publish Date: 2026-08-27

URL: CVE-2026-59313

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-27

Fix Resolution (org.springframework:spring-webmvc): 7.0.9

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8

Step up your Open Source Security Game with Mend here

CVE-2026-47891

Vulnerable Library - spring-web-7.0.6.jar

Spring Web

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-web/7.0.6/2baeb353efd42374239cc45e8d02780d6c6e7a77/spring-web-7.0.6.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • spring-boot-web-server-4.0.4.jar
          • spring-web-7.0.6.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier

Publish Date: 2026-08-27

URL: CVE-2026-47891

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-27

Fix Resolution (org.springframework:spring-web): 7.0.9

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8

Step up your Open Source Security Game with Mend here

CVE-2026-47890

Vulnerable Library - spring-webmvc-7.0.6.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-webmvc-4.0.4.jar
      • spring-webmvc-7.0.6.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19

Publish Date: 2026-08-27

URL: CVE-2026-47890

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2026-47890

Release Date: 2026-08-27

Fix Resolution (org.springframework:spring-webmvc): 7.0.9

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8

Step up your Open Source Security Game with Mend here

CVE-2026-47884

Vulnerable Library - spring-webmvc-7.0.6.jar

Spring Web MVC

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-webmvc/7.0.6/da516a887d0fea326c16b07fb2519f7f112f8eda/spring-webmvc-7.0.6.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-webmvc-4.0.4.jar
      • spring-webmvc-7.0.6.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-08-27

URL: CVE-2026-47884

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-27

Fix Resolution (org.springframework:spring-webmvc): 7.0.9

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8

Step up your Open Source Security Game with Mend here

CVE-2026-43512

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0.
Older unsupported versions any also be affect
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

Publish Date: 2026-05-12

URL: CVE-2026-43512

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-12

Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat:tomcat-catalina:11.0.22,org.apache.tomcat:tomcat-catalina:9.0.118,org.apache.tomcat:tomcat-catalina:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,https://github.com/apache/tomcat.git - 9.0.118

Step up your Open Source Security Game with Mend here

CVE-2026-41293

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Improper Input Validation vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27.
Older, end of support versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

Publish Date: 2026-05-12

URL: CVE-2026-41293

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-12

Fix Resolution: org.apache.tomcat:tomcat-coyote:9.0.118,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-coyote:11.0.22,org.apache.tomcat:tomcat-coyote:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,https://github.com/apache/tomcat.git - 9.0.118,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118

Step up your Open Source Security Game with Mend here

CVE-2026-68525

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

Publish Date: 2026-08-25

URL: CVE-2026-68525

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,org.apache.tomcat:tomcat-catalina:10.1.59,https://github.com/apache/tomcat.git - 9.0.121,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,https://github.com/apache/tomcat.git - 10.1.58,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:11.0.25

Step up your Open Source Security Game with Mend here

CVE-2026-65182

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.

Publish Date: 2026-08-25

URL: CVE-2026-65182

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: org.apache.tomcat.embed:tomcat-embed-core:11.0.25,org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat:tomcat-catalina:10.1.59,org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 11.0.25,https://github.com/apache/tomcat.git - 10.1.58,https://github.com/apache/tomcat.git - 9.0.121

Step up your Open Source Security Game with Mend here

CVE-2026-59283

Vulnerable Library - spring-expression-7.0.6.jar

Spring Expression Language (SpEL)

Library home page: https://github.com/spring-projects/spring-framework

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework/spring-expression/7.0.6/c00c73c545c81e2eae224a46a7c509fca74a2860/spring-expression-7.0.6.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-webmvc-4.0.4.jar
      • spring-webmvc-7.0.6.jar
        • spring-expression-7.0.6.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier

Publish Date: 2026-08-27

URL: CVE-2026-59283

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-27

Fix Resolution (org.springframework:spring-expression): 7.0.9

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8

Step up your Open Source Security Game with Mend here

CVE-2026-59084

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.

Publish Date: 2026-07-14

URL: CVE-2026-59084

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7

Release Date: 2026-07-14

Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.24

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8

Step up your Open Source Security Game with Mend here

CVE-2026-59083

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.

Publish Date: 2026-07-14

URL: CVE-2026-59083

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-14

Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.24

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.8

Step up your Open Source Security Game with Mend here

CVE-2026-43515

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

Publish Date: 2026-05-12

URL: CVE-2026-43515

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-12

Fix Resolution: org.apache.tomcat:tomcat-catalina:11.0.22,https://github.com/apache/tomcat.git - 11.0.22,org.apache.tomcat:tomcat-catalina:10.1.55,org.apache.tomcat.embed:tomcat-embed-core:10.1.55,https://github.com/apache/tomcat.git - 10.1.55,org.apache.tomcat.embed:tomcat-embed-core:9.0.118,org.apache.tomcat:tomcat-catalina:9.0.118,https://github.com/apache/tomcat.git - 9.0.118

Step up your Open Source Security Game with Mend here

CVE-2026-40976

Vulnerable Library - spring-boot-4.0.4.jar

Spring Boot

Library home page: https://spring.io/projects/spring-boot

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.springframework.boot/spring-boot/4.0.4/93d6e7c5b747d640bbad17971c5ce957bee88c5f/spring-boot-4.0.4.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • spring-boot-web-server-4.0.4.jar
          • spring-boot-4.0.4.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

Publish Date: 2026-04-27

URL: CVE-2026-40976

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-04-27

Fix Resolution: org.springframework.boot:spring-boot-security:4.0.6,https://github.com/spring-projects/spring-boot.git - v4.0.6

Step up your Open Source Security Game with Mend here

CVE-2026-29145

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13.
Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.

Publish Date: 2026-04-09

URL: CVE-2026-29145

CVSS 3 Score Details (9.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-04-09

Fix Resolution (org.apache.tomcat.embed:tomcat-embed-core): 11.0.20

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-web): 4.0.5

Step up your Open Source Security Game with Mend here

CVE-2026-68569

Vulnerable Library - tomcat-embed-core-11.0.18.jar

Core Tomcat implementation

Library home page: https://tomcat.apache.org/

Sample Path to Dependency File: /build.gradle.kts

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-core/11.0.18/a96bb1b8a21ee7e93ce01cce7fd63f8e7561ec92/tomcat-embed-core-11.0.18.jar

Dependency Hierarchy:

  • spring-boot-starter-web-4.0.4.jar (Root Library)
    • spring-boot-starter-tomcat-4.0.4.jar
      • spring-boot-starter-tomcat-runtime-4.0.4.jar
        • tomcat-embed-core-11.0.18.jar (Vulnerable Library)

Found in HEAD commit: 9200939ed00ea9c0f2341f87024dc603fe2b491c

Found in base branch: master

Vulnerability Details

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

Publish Date: 2026-08-25

URL: CVE-2026-68569

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-25

Fix Resolution: org.apache.tomcat:tomcat-catalina:11.0.25,org.apache.tomcat:tomcat-catalina:9.0.121,org.apache.tomcat.embed:tomcat-embed-core:11.0.25,org.apache.tomcat.embed:tomcat-embed-core:10.1.59,org.apache.tomcat:tomcat-catalina:10.1.59,org.apache.tomcat.embed:tomcat-embed-core:9.0.121,https://github.com/apache/tomcat.git - 10.1.58,https://github.com/apache/tomcat.git - 11.0.25,https://github.com/apache/tomcat.git - 9.0.121

Step up your Open Source Security Game with Mend here

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions