Package
kayenta-fips-2025.4
Component
spring-webflux
Latest update
5.9
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Spring Framework 6.0.x and 6.1.x are unpatched for GHSA-4773-3jfm-qmx3 (CVE-2026-22737) per the upstream advisory; the fix lands in 6.2.17. Kayenta bundles spring-webflux/spring-webmvc 6.0.23 via its pinned Spring Boot dependency, so reaching a fixed branch requires an upstream Kayenta release on a newer Spring Boot major version that pulls in Spring Framework 6.2.x+. Waiting on that upstream bump.
Status