Package
ontop
Component
spring-boot-starter-actuator
Latest update
8.2
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The spring-boot-starter-actuator vulnerability (CVE-2026-22733) affects version 2.7.18 at /opt/ontop/lib/spring-boot-starter-actuator-2.7.18.jar. Spring Boot 2.7.x is end-of-life — no patched version exists for this branch. The fix is only available in Spring Boot 3.5.12+ and 4.0.4+, which represent major version upgrades requiring upstream ontop to migrate from Spring Boot 2.x to 3.x+.
Status