[Git][security-tracker-team/security-tracker][master] new spring issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Sep 4 14:42:01 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
dc2e1ea1 by Moritz Muehlenhoff at 2026-09-04T15:41:18+02:00
new spring issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7323,27 +7323,45 @@ CVE-2026-49809 (Dell PowerProtect Cyber Recovery, versions 20.2 and prior, conta
CVE-2026-47894 (Spring Cloud Config Server native environment repository allows exposu ...)
NOT-FOR-US: VMware
CVE-2026-47893 (A Spring WebFlux application that supports WebSocket connections may e ...)
- TODO: check
+ - libspring-java <unfixed> (unimportant)
+ NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+ NOTE: https://spring.io/security/cve-2026-47893
CVE-2026-47892 (A WebFlux application using functional endpoints and deployed with Dis ...)
- TODO: check
+ - libspring-java <unfixed> (unimportant)
+ NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+ NOTE: https://spring.io/security/cve-2026-47892
CVE-2026-47891 (A Spring WebFlux application that relies on the Aalto XML processor to ...)
- TODO: check
+ - libspring-java <unfixed> (unimportant)
+ NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+ NOTE: https://spring.io/security/cve-2026-47891
CVE-2026-47890 (Spring MVC and WebFlux applications are vulnerable to stream corruptio ...)
- TODO: check
+ - libspring-java <not-affected> (Only affects 6.2 and later)
+ NOTE: https://spring.io/security/cve-2026-47890
CVE-2026-47889 (A WebFlux application running on the Jetty 12 Core reactive adapter se ...)
- TODO: check
+ - libspring-java <not-affected> (Only affects 6.2 and later)
+ NOTE: https://spring.io/security/cve-2026-47889
CVE-2026-47888 (A Spring RSocket application is exposed to a memory leak via a malform ...)
- TODO: check
+ - libspring-java <unfixed> (unimportant)
+ NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+ NOTE: https://spring.io/security/cve-2026-47888
CVE-2026-47887 (A Spring MVC application that uses UrlFileNameViewController that is m ...)
- TODO: check
+ - libspring-java <unfixed> (unimportant)
+ NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+ NOTE: https://spring.io/security/cve-2026-47887
CVE-2026-47886 (Applications that evaluate user-supplied Spring Expression Language (S ...)
- TODO: check
+ - libspring-java <unfixed> (unimportant)
+ NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+ NOTE: https://spring.io/security/cve-2026-47886
CVE-2026-47885 (The PartEventHttpMessageReader in Spring WebFlux does not enforce the ...)
- TODO: check
+ - libspring-java <not-affected> (Only affects 6.1 and later)
+ NOTE: https://spring.io/security/cve-2026-47885
CVE-2026-47884 (Use of XsltView in a Spring MVC application can result in SSRF and RCE ...)
- TODO: check
+ - libspring-java <unfixed> (unimportant)
+ NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+ NOTE: https://spring.io/security/cve-2026-47884
CVE-2026-47883 (UrlHandlerFilter can be vulnerable to an open redirect when configured ...)
- TODO: check
+ - libspring-java <not-affected> (Only affects 6.2 and later)
+ NOTE: https://spring.io/security/cve-2026-47883
CVE-2026-47881 (Spring Batch's FlatFileItemReader supports files where a single logica ...)
TODO: check
CVE-2026-47880 (A producer who can publish to a JMS destination consumed by any Spring ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc2e1ea1357f749a362ccb76ba275aed510f1cf1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc2e1ea1357f749a362ccb76ba275aed510f1cf1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/3e876c5f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list