camunda-zeebe-8.6
Chainguard
7.3
CVSS V3
Status
Impact
CVE-2025-46701 is a CGI security constraint bypass in Apache tomcat-embed-core, which is a transitive dependency of Spring Boot. Spring Boot v3.5.0 updates this dependency and remediates the CVE, unfortunately camunda-zeebe cannot be upgraded to use the newer spring-boot version without upstream code changes being made.
Status