Package
ontop-fips
Component
spring-boot-autoconfigure
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
ontop bundles spring-boot 2.7.18. Spring Boot 2.7.x is OSS end-of-life and CVE-2026-41001 has no OSS fix in that line (vulnerable through 2.7.32); the fix is only in Spring Boot 3.5.15 / 4.0.7, which require Java 17 and the jakarta EE namespace migration. Upstream has explicitly declined to migrate: ontop/ontop#865 states the move to Spring Boot 3.x / Java 17 is blocked because they still support Java 11 users. Both the latest release (5.5.0) and the dev branch (version5) remain on Spring Boot 2.7.18.
Status