Package
kayenta-2026.0
Component
spring-webflux
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Spring Framework 6.0.x is unpatched for GHSA-g5vr-rgqm-vf78 (CVE-2024-38819) per the upstream advisory; the fix lands in 6.1.14. Kayenta bundles spring-webflux/spring-webmvc 6.0.23 via its pinned Spring Boot dependency, so reaching a fixed branch requires an upstream Kayenta release on a newer Spring Boot major version that pulls in Spring Framework 6.1.x+. Waiting on that upstream bump.
Status