Package
kayenta-2026.0
Component
spring-context
Latest update
3.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Spring Framework 6.0.x is unpatched for GHSA-4gc7-5j7h-4qph (CVE-2024-38820) per the upstream advisory; the fix lands in 6.1.14. Kayenta bundles spring-context/spring-web 6.0.23 via its pinned Spring Boot dependency, so reaching a fixed branch requires an upstream Kayenta release on a newer Spring Boot major version that pulls in Spring Framework 6.1.x+. Waiting on that upstream bump.
Status