Package
ontop
Component
spring-expression
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
ontop bundles spring-expression 5.3.39 (via Spring Boot 2.7.18). Spring Framework 5.3.x is OSS end-of-life and CVE-2026-41851 has no OSS fix in that line (vulnerable through 5.3.48); the fix is only in Spring Framework 6.2.19 / 7.0.8, which require Java 17 and the jakarta EE namespace migration. Upstream has declined to migrate: ontop/ontop#865 states the move to Spring Boot 3.x / Java 17 is blocked because they still support Java 11 users.
Status