[Git][security-tracker-team/security-tracker][master] new spring issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 4 14:42:01 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dc2e1ea1 by Moritz Muehlenhoff at 2026-09-04T15:41:18+02:00
new spring issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7323,27 +7323,45 @@ CVE-2026-49809 (Dell PowerProtect Cyber Recovery, versions 20.2 and prior, conta
 CVE-2026-47894 (Spring Cloud Config Server native environment repository allows exposu ...)
 	NOT-FOR-US: VMware
 CVE-2026-47893 (A Spring WebFlux application that supports WebSocket connections may e ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+	NOTE: https://spring.io/security/cve-2026-47893
 CVE-2026-47892 (A WebFlux application using functional endpoints and deployed with Dis ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+	NOTE: https://spring.io/security/cve-2026-47892
 CVE-2026-47891 (A Spring WebFlux application that relies on the Aalto XML processor to ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+	NOTE: https://spring.io/security/cve-2026-47891
 CVE-2026-47890 (Spring MVC and WebFlux applications are vulnerable to stream corruptio ...)
-	TODO: check
+	- libspring-java <not-affected> (Only affects 6.2 and later)
+	NOTE: https://spring.io/security/cve-2026-47890
 CVE-2026-47889 (A WebFlux application running on the Jetty 12 Core reactive adapter se ...)
-	TODO: check
+	- libspring-java <not-affected> (Only affects 6.2 and later)
+	NOTE: https://spring.io/security/cve-2026-47889
 CVE-2026-47888 (A Spring RSocket application is exposed to a memory leak via a malform ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+	NOTE: https://spring.io/security/cve-2026-47888
 CVE-2026-47887 (A Spring MVC application that uses UrlFileNameViewController that is m ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+	NOTE: https://spring.io/security/cve-2026-47887
 CVE-2026-47886 (Applications that evaluate user-supplied Spring Expression Language (S ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+	NOTE: https://spring.io/security/cve-2026-47886
 CVE-2026-47885 (The PartEventHttpMessageReader in Spring WebFlux does not enforce the  ...)
-	TODO: check
+	- libspring-java <not-affected> (Only affects 6.1 and later)
+	NOTE: https://spring.io/security/cve-2026-47885
 CVE-2026-47884 (Use of XsltView in a Spring MVC application can result in SSRF and RCE ...)
-	TODO: check
+	- libspring-java <unfixed> (unimportant)
+	NOTE: Only supported for building applications shipped in Debian, see README.Debian.security
+	NOTE: https://spring.io/security/cve-2026-47884
 CVE-2026-47883 (UrlHandlerFilter can be vulnerable to an open redirect when configured ...)
-	TODO: check
+	- libspring-java <not-affected> (Only affects 6.2 and later)
+	NOTE: https://spring.io/security/cve-2026-47883
 CVE-2026-47881 (Spring Batch's FlatFileItemReader supports files where a single logica ...)
 	TODO: check
 CVE-2026-47880 (A producer who can publish to a JMS destination consumed by any Spring ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc2e1ea1357f749a362ccb76ba275aed510f1cf1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dc2e1ea1357f749a362ccb76ba275aed510f1cf1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/3e876c5f/attachment.htm>


More information about the debian-security-tracker-commits mailing list