Package
kayenta-2026.1
Component
spring-security-crypto
Latest update
7.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Spring Security 6.1.x patches for CVE-2025-22228 are Enterprise Support Only (commercial Tanzu Spring subscription); the public 6.1.x OSS line ended at 6.1.9 and the fix landed only in 6.1.14 behind a paywall. OSS fixes are available in 6.3.8 and 6.4.4, but bumping past the 6.1.x line requires upgrading Spring Boot beyond 3.1.x (the version pinned by Spinnaker's BOM in kayenta-2026.1). See https://spring.io/security/cve-2025-22228.
Status