Update version.springframework to v6 - #27
Security Report
You have successfully remediated 42 vulnerabilities, but introduced 19 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2025-41249Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.1.20/spring-core-6.1.20.jar Dependency Hierarchy: -> spring-context-6.1.20.jar (Root Library) -> spring-aop-6.1.20.jar -> spring-beans-6.1.20.jar -> ❌ spring-core-6.1.20.jar (Vulnerable Library) |
7.5 | Transitive spring-core-6.1.20.jar |
spring-context-6.1.20.jar | Transitive https://github.com/spring-projects/spring-framework.git - v6.2.11,org.springframework:spring-core:6.2.11 |
None | ||
CVE-2025-41234Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.1.20/spring-web-6.1.20.jar Dependency Hierarchy: -> ❌ spring-web-6.1.20.jar (Vulnerable Library) |
6.5 | Direct spring-web-6.1.20.jar |
spring-web-6.1.20.jar | 6.1.21 | None | ||
CVE-2026-41848Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.1.20/spring-core-6.1.20.jar Dependency Hierarchy: -> spring-context-6.1.20.jar (Root Library) -> spring-aop-6.1.20.jar -> spring-beans-6.1.20.jar -> ❌ spring-core-6.1.20.jar (Vulnerable Library) |
3.7 | Transitive spring-core-6.1.20.jar |
spring-context-6.1.20.jar | Transitive https://github.com/spring-projects/spring-framework.git - v7.0.8,org.springframework:spring-core:7.0.8,https://github.com/spring-projects/spring-framework.git - v6.2.19,org.springframework:spring-core:6.2.19 |
None | ||
CVE-2026-41850Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.1.20/spring-expression-6.1.20.jar Dependency Hierarchy: -> spring-context-6.1.20.jar (Root Library) -> ❌ spring-expression-6.1.20.jar (Vulnerable Library) |
7.5 | Transitive spring-expression-6.1.20.jar |
spring-context-6.1.20.jar | Transitive org.springframework:spring-expression:7.0.8,https://github.com/spring-projects/spring-framework.git - v6.2.19,https://github.com/spring-projects/spring-framework.git - v7.0.8,org.springframework:spring-expression:6.2.19 |
None | ||
CVE-2026-41842Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.1.20/spring-webmvc-6.1.20.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.1.20.jar (Vulnerable Library) |
7.5 | Direct spring-webmvc-6.1.20.jar |
spring-webmvc-6.1.20.jar | org.springframework:spring-webflux:6.2.19,org.springframework:spring-webmvc:6.2.19,org.springframework:spring-webmvc:7.0.8,org.springframework:spring-webflux:7.0.8,https://github.com/spring-projects/spring-framework.git - v7.0.8,https://github.com/spring-projects/spring-framework.git - v6.2.19 | None | ||
CVE-2026-41845Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.1.20/spring-webmvc-6.1.20.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.1.20.jar (Vulnerable Library) |
7.1 | Direct spring-webmvc-6.1.20.jar |
spring-webmvc-6.1.20.jar | https://github.com/spring-projects/spring-framework.git - v7.0.8,org.springframework:spring-web:6.2.19,https://github.com/spring-projects/spring-framework.git - v6.2.19,org.springframework:spring-web:7.0.8 | None | ||
CVE-2026-41846Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.1.20/spring-webmvc-6.1.20.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.1.20.jar (Vulnerable Library) |
5.9 | Direct spring-webmvc-6.1.20.jar |
spring-webmvc-6.1.20.jar | https://github.com/spring-projects/spring-framework.git - v7.0.8,org.springframework:spring-webmvc:6.2.19,org.springframework:spring-webmvc:7.0.8,https://github.com/spring-projects/spring-framework.git - v6.2.19 | None | ||
CVE-2026-41843Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.1.20/spring-webmvc-6.1.20.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.1.20.jar (Vulnerable Library) |
5.9 | Direct spring-webmvc-6.1.20.jar |
spring-webmvc-6.1.20.jar | https://github.com/spring-projects/spring-framework.git - v7.0.8,https://github.com/spring-projects/spring-framework.git - v6.2.19,org.springframework:spring-webmvc:7.0.8,org.springframework:spring-webflux:7.0.8,org.springframework:spring-webflux:6.2.19,org.springframework:spring-webmvc:6.2.19 | None | ||
CVE-2026-41841Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.1.20/spring-webmvc-6.1.20.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.1.20.jar (Vulnerable Library) |
5.9 | Direct spring-webmvc-6.1.20.jar |
spring-webmvc-6.1.20.jar | org.springframework:spring-webmvc:7.0.8,https://github.com/spring-projects/spring-framework.git - v6.2.19,org.springframework:spring-webflux:7.0.8,org.springframework:spring-webmvc:6.2.19,org.springframework:spring-webflux:6.2.19,https://github.com/spring-projects/spring-framework.git - v7.0.8 | None | ||
CVE-2025-41242Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.1.20/spring-webmvc-6.1.20.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.1.20.jar (Vulnerable Library) |
5.9 | Direct spring-webmvc-6.1.20.jar |
spring-webmvc-6.1.20.jar | https://github.com/spring-projects/spring-framework.git - v6.2.10,org.springframework:spring-beans:6.2.10 | None | ||
CVE-2026-41853Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.1.20/spring-webmvc-6.1.20.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.1.20.jar (Vulnerable Library) |
5.3 | Direct spring-webmvc-6.1.20.jar |
spring-webmvc-6.1.20.jar | https://github.com/spring-projects/spring-framework.git - v6.2.19,org.springframework:spring-web:7.0.8,https://github.com/spring-projects/spring-framework.git - v7.0.8,org.springframework:spring-web:6.2.19 | None | ||
CVE-2026-41851Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.1.20/spring-expression-6.1.20.jar Dependency Hierarchy: -> spring-context-6.1.20.jar (Root Library) -> ❌ spring-expression-6.1.20.jar (Vulnerable Library) |
5.3 | Transitive spring-expression-6.1.20.jar |
spring-context-6.1.20.jar | Transitive https://github.com/spring-projects/spring-framework.git - v6.2.19,org.springframework:spring-expression:7.0.8,https://github.com/spring-projects/spring-framework.git - v7.0.8,org.springframework:spring-expression:6.2.19 |
None | ||
CVE-2026-22745Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.1.20/spring-webmvc-6.1.20.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.1.20.jar (Vulnerable Library) |
5.3 | Direct spring-webmvc-6.1.20.jar |
spring-webmvc-6.1.20.jar | 6.2.18 | None | ||
CVE-2026-41844Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.1.20/spring-webmvc-6.1.20.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.1.20.jar (Vulnerable Library) |
4.2 | Direct spring-webmvc-6.1.20.jar |
spring-webmvc-6.1.20.jar | https://github.com/spring-projects/spring-framework.git - v6.2.19,org.springframework:spring-webflux:6.2.19,https://github.com/spring-projects/spring-framework.git - v7.0.8,org.springframework:spring-webmvc:7.0.8,org.springframework:spring-webmvc:6.2.19,org.springframework:spring-webflux:7.0.8 | None | ||
CVE-2026-41852Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.1.20/spring-expression-6.1.20.jar Dependency Hierarchy: -> spring-context-6.1.20.jar (Root Library) -> ❌ spring-expression-6.1.20.jar (Vulnerable Library) |
3.7 | Transitive spring-expression-6.1.20.jar |
spring-context-6.1.20.jar | Transitive https://github.com/spring-projects/spring-framework.git - v7.0.8,org.springframework:spring-expression:7.0.8,https://github.com/spring-projects/spring-framework.git - v6.2.19,org.springframework:spring-expression:6.2.19 |
None | ||
CVE-2026-22741Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.1.20/spring-webmvc-6.1.20.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.1.20.jar (Vulnerable Library) |
3.1 | Direct spring-webmvc-6.1.20.jar |
spring-webmvc-6.1.20.jar | https://github.com/spring-projects/spring-framework.git - v7.0.7,https://github.com/spring-projects/spring-framework.git - v6.2.18,org.springframework:spring-webmvc:6.2.18,org.springframework:spring-webmvc:7.0.7,org.springframework:spring-webflux:7.0.7,org.springframework:spring-webflux:6.2.18 | None | ||
CVE-2026-22735Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.1.20/spring-webmvc-6.1.20.jar Dependency Hierarchy: -> ❌ spring-webmvc-6.1.20.jar (Vulnerable Library) |
2.6 | Direct spring-webmvc-6.1.20.jar |
spring-webmvc-6.1.20.jar | https://github.com/spring-projects/spring-framework.git - v6.2.17,https://github.com/spring-projects/spring-framework.git - v7.0.6,org.springframework:spring-webmvc:6.2.17,org.springframework:spring-web:6.2.17,org.springframework:spring-web:7.0.6,https://github.com/spring-projects/spring-framework.git - v6.1.21,https://github.com/spring-projects/spring-framework.git - v7.0.6,org.springframework:spring-webmvc:7.0.6,https://github.com/spring-projects/spring-framework.git - v6.2.17,org.springframework:spring-webmvc:6.2.17,org.springframework:spring-web:6.2.17,org.springframework:spring-webmvc:7.0.6,org.springframework:spring-web:7.0.6,https://github.com/spring-projects/spring-framework.git - v6.1.21 | None | ||
CVE-2018-1257Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.1.20/spring-core-6.1.20.jar Dependency Hierarchy: -> spring-context-6.1.20.jar (Root Library) -> spring-aop-6.1.20.jar -> spring-beans-6.1.20.jar -> ❌ spring-core-6.1.20.jar (Vulnerable Library) |
6.5 | Transitive spring-core-6.1.20.jar |
spring-context-6.1.20.jar | Transitive 5.0.6,4.3.17 |
None | ||
CVE-2018-1271Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.1.20/spring-core-6.1.20.jar Dependency Hierarchy: -> spring-context-6.1.20.jar (Root Library) -> spring-aop-6.1.20.jar -> spring-beans-6.1.20.jar -> ❌ spring-core-6.1.20.jar (Vulnerable Library) |
5.9 | Transitive spring-core-6.1.20.jar |
spring-context-6.1.20.jar | Transitive org.springframework:spring-webflux:5.0.5.RELEASE,org.springframework:spring-webmvc:4.3.15.RELEASE,5.0.5.RELEASE |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2022-22965 | spring-beans-4.3.30.RELEASE.jar |
| CVE-2024-38820 | spring-webmvc-4.3.30.RELEASE.jar |
| GHSA-7c2q-5qmr-v76q | esapi-2.3.0.0.jar |
| CVE-2016-1000027 | spring-web-4.3.30.RELEASE.jar |
| CVE-2025-41249 | spring-core-4.3.30.RELEASE.jar |
| CVE-2024-38820 | spring-core-4.3.30.RELEASE.jar |
| CVE-2026-41852 | spring-expression-4.3.30.RELEASE.jar |
| CVE-2024-22243 | spring-web-4.3.30.RELEASE.jar |
| CVE-2024-38820 | spring-web-4.3.30.RELEASE.jar |
| CVE-2026-41848 | spring-core-4.3.30.RELEASE.jar |
| CVE-2021-22096 | spring-web-4.3.30.RELEASE.jar |
| CVE-2024-38819 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2022-22970 | spring-core-4.3.30.RELEASE.jar |
| CVE-2026-41846 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2024-38828 | spring-core-4.3.30.RELEASE.jar |
| CVE-2026-41844 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2026-41842 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2018-1257 | spring-core-4.3.30.RELEASE.jar |
| CVE-2025-22233 | spring-context-4.3.30.RELEASE.jar |
| CVE-2023-20861 | spring-expression-4.3.30.RELEASE.jar |
| CVE-2024-38809 | spring-web-4.3.30.RELEASE.jar |
| CVE-2024-38828 | spring-web-4.3.30.RELEASE.jar |
| CVE-2026-41849 | spring-expression-4.3.30.RELEASE.jar |
| CVE-2026-22745 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2021-22096 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2026-41851 | spring-expression-4.3.30.RELEASE.jar |
| CVE-2024-22259 | spring-web-4.3.30.RELEASE.jar |
| CVE-2026-22741 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2026-41850 | spring-expression-4.3.30.RELEASE.jar |
| GHSA-257q-pv89-v3xv | jquery-2.1.4.min.js |
| CVE-2018-1271 | spring-core-4.3.30.RELEASE.jar |
| CVE-2023-20863 | spring-expression-4.3.30.RELEASE.jar |
| CVE-2024-38816 | spring-webmvc-4.3.30.RELEASE.jar |
| GHSA-r68h-jhhj-9jvm | esapi-2.3.0.0.jar |
| CVE-2026-41853 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2024-22262 | spring-web-4.3.30.RELEASE.jar |
| CVE-2026-41845 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2026-41841 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2026-41843 | spring-webmvc-4.3.30.RELEASE.jar |
| GHSA-257q-pv89-v3xv | jquery-1.11.3.min.js |
| CVE-2026-22735 | spring-webmvc-4.3.30.RELEASE.jar |
| CVE-2024-38808 | spring-expression-4.3.30.RELEASE.jar |
Base branch total remaining vulnerabilities: 89
Base branch commit: ebfb28b0c8f03b37017fb2e66087888ad08b1806
Total libraries scanned: 101
Scan token: 8b164a51ae3a4b68933fb9b051e45c32