Package
kayenta-fips-2025.4
Component
spring-webmvc
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Spring Framework 6.0.x is unpatched for GHSA-cx7f-g6mp-7hqm (CVE-2024-38816) per the upstream advisory; the fix lands in 6.1.13. Kayenta bundles spring-webflux/spring-webmvc 6.0.23 via its pinned Spring Boot dependency, so reaching a fixed branch requires an upstream Kayenta release on a newer Spring Boot major version that pulls in Spring Framework 6.1.x+. Waiting on that upstream bump.
Status