[Git][security-tracker-team/security-tracker][master] new libspring-security-2.0-java libspring-java issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 31 17:32:23 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2ed18048 by Moritz Muehlenhoff at 2026-08-31T18:31:53+02:00
new libspring-security-2.0-java libspring-java issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2292,9 +2292,13 @@ CVE-2026-59316 (Spring Authorization Server's default consent page renders user-
 CVE-2026-59315 (The Spring Cloud Config Monitor is susceptible to Denial of Service at ...)
 	NOT-FOR-US: VMware
 CVE-2026-59314 (Applications that build a Content-Disposition header value from untrus ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: https://spring.io/security/cve-2026-59314
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
 CVE-2026-59313 (Spring MVC applications using the functional web framework are vulnera ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: https://spring.io/security/cve-2026-59313
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
 CVE-2026-59311 (A local unprivileged user on the same host can redirect all Zip/UnZip  ...)
 	NOT-FOR-US: VMware
 CVE-2026-59307 (An operator who calls JdbcMessageStore.addAllowedPatterns(...) to rest ...)
@@ -2340,15 +2344,23 @@ CVE-2026-59285 (Spring for GraphQL applications are vulnerable to Unsafe Deseria
 CVE-2026-59284 (There is no allow list for property keys when Spring Cloud Commons wri ...)
 	NOT-FOR-US: VMware
 CVE-2026-59283 (Applications that evaluate Spring Expression Language (SpEL) expressio ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: https://spring.io/security/cve-2026-59283
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
 CVE-2026-59282 (Spring Framework applications that use Spring's data binding infrastru ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: https://spring.io/security/cve-2026-59282
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
 CVE-2026-59281 (Spring MVC and WebFlux applications that obtain a data-binding Errors  ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: https://spring.io/security/cve-2026-59281
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
 CVE-2026-59277 (Spring Security's InetAddressMatchers utility provides matchInternal() ...)
-	TODO: check
+	- libspring-security-2.0-java <not-affected> (Only affects 7.x)
+	NOTE: https://spring.io/security/cve-2026-59277
 CVE-2026-59276 (Several components in Spring Security compare security-sensitive value ...)
-	TODO: check
+	- libspring-security-2.0-java <removed>
+	NOTE: https://spring.io/security/cve-2026-59276
 CVE-2026-55758 (CC: Tweaked is a mod for Minecraft which adds programmable computers,  ...)
 	NOT-FOR-US: CC: Tweaked (mod for Minecraft)
 CVE-2026-54732 (libreoffice-convert is a Node.js module for converting office document ...)
@@ -2876,9 +2888,12 @@ CVE-2026-5218 (Improper neutralization of Script-Related HTML tags in a web page
 CVE-2026-59355 (In versions of Spring Authorization Server 1.5.0 through 1.5.7, the au ...)
 	NOT-FOR-US: VMware
 CVE-2026-59354 (In versions of Spring Security's OAuth2 Authorization Server module 7. ...)
-	TODO: check
+	- libspring-security-2.0-java <not-affected> (Only affects 7.x)
+	NOTE: https://spring.io/security/cve-2026-59354
 CVE-2026-59280 (Applications using Spring Framework's FreeMarker integration may be vu ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: https://spring.io/security/cve-2026-59280
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
 CVE-2026-59272 (Any application shipping logs to RabbitMQ over TLS via the Log4j2 appe ...)
 	NOT-FOR-US: VMware
 CVE-2026-57499 (Liman is open source server management software. Prior to 2.2.2 - 1103 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ed18048bf4ddd72f37674b1a878b10d7f10a8a1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ed18048bf4ddd72f37674b1a878b10d7f10a8a1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/6f412411/attachment.htm>


More information about the debian-security-tracker-commits mailing list