Skip to content

Update spring.version to v6

d39ca87
Select commit
Loading
Failed to load commit list.
Open

Update spring.version to v6 (major) #216

Update spring.version to v6
d39ca87
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Feb 9, 2026 in 11m 43s

Security Report

You have successfully remediated 69 vulnerabilities, but introduced 15 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2024-22259

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar

Dependency Hierarchy:

-> ❌ spring-web-6.0.0.jar (Vulnerable Library)

High 8.1 Direct spring-web-6.0.0.jar spring-web-6.0.0.jar org.springframework:spring-web:6.1.5,org.springframework:spring-web:6.0.18,org.springframework:spring-web:5.3.33 None

Reachable

CVE-2024-22243

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar

Dependency Hierarchy:

-> ❌ spring-web-6.0.0.jar (Vulnerable Library)

High 8.1 Direct spring-web-6.0.0.jar spring-web-6.0.0.jar org.springframework:spring-web:6.1.4,org.springframework:spring-web:5.3.32,org.springframework:spring-web:6.0.17 None

Reachable

CVE-2025-41249

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.0.0/spring-core-6.0.0.jar

Dependency Hierarchy:

-> spring-web-6.0.0.jar (Root Library)

   -> spring-beans-6.0.0.jar

     -> ❌ spring-core-6.0.0.jar (Vulnerable Library)

High 7.5 Transitive spring-core-6.0.0.jar spring-web-6.0.0.jar Transitive https://github.com/spring-projects/spring-framework.git - v6.2.11,org.springframework:spring-core:6.2.11 None

Reachable

CVE-2024-38819

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.0.0/spring-webmvc-6.0.0.jar

Dependency Hierarchy:

-> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library)

High 7.5 Direct spring-webmvc-6.0.0.jar spring-webmvc-6.0.0.jar org.springframework:spring-webmvc:6.1.14,org.springframework:spring-webflux:6.1.14 None

Reachable

CVE-2023-20860

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.0.0/spring-webmvc-6.0.0.jar

Dependency Hierarchy:

-> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library)

High 7.5 Direct spring-webmvc-6.0.0.jar spring-webmvc-6.0.0.jar org.springframework:spring-webmvc:6.0.7,org.springframework:spring-webmvc:5.3.26,org.springframework:spring-webmvc:5.3.26,org.springframework:spring-webmvc:6.0.7,org.springframework:spring:5.3.26 None

Reachable

CVE-2025-41234

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar

Dependency Hierarchy:

-> ❌ spring-web-6.0.0.jar (Vulnerable Library)

Medium 6.5 Direct spring-web-6.0.0.jar spring-web-6.0.0.jar org.springframework:spring-web:6.1.21,org.springframework:spring-web:6.2.8,https://github.com/spring-projects/spring-framework.git - v6.1.21,https://github.com/spring-projects/spring-framework.git - v6.2.8 None

Reachable

CVE-2023-20863

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar

Dependency Hierarchy:

-> spring-webmvc-6.0.0.jar (Root Library)

   -> spring-context-6.0.0.jar

     -> ❌ spring-expression-6.0.0.jar (Vulnerable Library)

Medium 6.5 Transitive spring-expression-6.0.0.jar spring-webmvc-6.0.0.jar Transitive 6.0.8 #184

Reachable

CVE-2023-20861

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-expression/6.0.0/spring-expression-6.0.0.jar

Dependency Hierarchy:

-> spring-webmvc-6.0.0.jar (Root Library)

   -> spring-context-6.0.0.jar

     -> ❌ spring-expression-6.0.0.jar (Vulnerable Library)

Medium 6.5 Transitive spring-expression-6.0.0.jar spring-webmvc-6.0.0.jar Transitive 6.0.7 #183

Reachable

CVE-2025-41242

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.0.0/spring-webmvc-6.0.0.jar

Dependency Hierarchy:

-> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library)

Medium 5.9 Direct spring-webmvc-6.0.0.jar spring-webmvc-6.0.0.jar https://github.com/spring-projects/spring-framework.git - v6.2.10,org.springframework:spring-beans:6.2.10 None

Reachable

CVE-2024-38809

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar

Dependency Hierarchy:

-> ❌ spring-web-6.0.0.jar (Vulnerable Library)

Medium 5.3 Direct spring-web-6.0.0.jar spring-web-6.0.0.jar org.springframework:spring-web:6.0.23,org.springframework:spring-web:6.1.12,org.springframework:spring-web:5.3.38 None

Reachable

CVE-2025-22233

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-context/6.0.0/spring-context-6.0.0.jar

Dependency Hierarchy:

-> spring-webmvc-6.0.0.jar (Root Library)

   -> ❌ spring-context-6.0.0.jar (Vulnerable Library)

Low 3.1 Transitive spring-context-6.0.0.jar spring-webmvc-6.0.0.jar Transitive https://github.com/spring-projects/spring-framework.git - v6.1.20 ,org.springframework:spring-context:6.1.20,org.springframework:spring-context:6.2.7,https://github.com/spring-projects/spring-framework.git - v6.2.7 None

Reachable

CVE-2024-38820

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/6.0.0/spring-web-6.0.0.jar

Dependency Hierarchy:

-> ❌ spring-web-6.0.0.jar (Vulnerable Library)

Low 3.1 Direct spring-web-6.0.0.jar spring-web-6.0.0.jar org.springframework:spring-context:6.1.14 None

Reachable

CVE-2018-1257

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.0.0/spring-core-6.0.0.jar

Dependency Hierarchy:

-> spring-web-6.0.0.jar (Root Library)

   -> spring-beans-6.0.0.jar

     -> ❌ spring-core-6.0.0.jar (Vulnerable Library)

Medium 6.5 Transitive spring-core-6.0.0.jar spring-web-6.0.0.jar Transitive 5.0.6,4.3.17 #148
CVE-2018-1271

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/6.0.0/spring-core-6.0.0.jar

Dependency Hierarchy:

-> spring-web-6.0.0.jar (Root Library)

   -> spring-beans-6.0.0.jar

     -> ❌ spring-core-6.0.0.jar (Vulnerable Library)

Medium 5.9 Transitive spring-core-6.0.0.jar spring-web-6.0.0.jar Transitive org.springframework:spring-webflux:5.0.5.RELEASE,org.springframework:spring-webmvc:4.3.15.RELEASE,5.0.5.RELEASE #109
CVE-2023-34053

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/6.0.0/spring-webmvc-6.0.0.jar

Dependency Hierarchy:

-> ❌ spring-webmvc-6.0.0.jar (Vulnerable Library)

Medium 5.3 Direct spring-webmvc-6.0.0.jar spring-webmvc-6.0.0.jar org.springframework:spring-webmvc:6.0.14 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2020-24750 jackson-databind-2.8.4.jar
CVE-2020-36185 jackson-databind-2.8.4.jar
CVE-2020-10650 jackson-databind-2.8.4.jar
CVE-2020-11112 jackson-databind-2.8.4.jar
CVE-2024-38820 spring-web-4.2.0.RELEASE.jar
CVE-2018-15756 spring-core-4.2.0.RELEASE.jar
CVE-2020-14062 jackson-databind-2.8.4.jar
CVE-2018-15756 spring-web-4.2.0.RELEASE.jar
CVE-2018-14718 jackson-databind-2.8.4.jar
CVE-2020-36518 jackson-databind-2.8.4.jar
CVE-2018-1271 spring-core-4.2.0.RELEASE.jar
CVE-2020-36187 jackson-databind-2.8.4.jar
CVE-2024-38808 spring-expression-4.2.0.RELEASE.jar
CVE-2025-41249 spring-core-4.2.0.RELEASE.jar
CVE-2020-14195 jackson-databind-2.8.4.jar
CVE-2018-1257 spring-core-4.2.0.RELEASE.jar
CVE-2020-9548 jackson-databind-2.8.4.jar
CVE-2016-1000027 spring-web-4.2.0.RELEASE.jar
CVE-2020-36179 jackson-databind-2.8.4.jar
CVE-2018-19361 jackson-databind-2.8.4.jar
CVE-2016-5007 spring-webmvc-4.2.0.RELEASE.jar
CVE-2023-20861 spring-expression-4.2.0.RELEASE.jar
GHSA-257q-pv89-v3xv jquery-3.2.1.min.js
CVE-2020-36180 jackson-databind-2.8.4.jar
CVE-2018-1271 spring-webmvc-4.2.0.RELEASE.jar
CVE-2020-36181 jackson-databind-2.8.4.jar
CVE-2019-17531 jackson-databind-2.8.4.jar
CVE-2025-22233 spring-context-4.2.0.RELEASE.jar
CVE-2024-38819 spring-webmvc-4.2.0.RELEASE.jar
CVE-2015-5211 spring-web-4.2.0.RELEASE.jar
CVE-2018-14721 jackson-databind-2.8.4.jar
CVE-2018-19362 jackson-databind-2.8.4.jar
WS-2016-7112 spring-context-4.2.0.RELEASE.jar
CVE-2021-22096 spring-webmvc-4.2.0.RELEASE.jar
CVE-2019-14540 jackson-databind-2.8.4.jar
CVE-2020-10673 jackson-databind-2.8.4.jar
CVE-2020-36186 jackson-databind-2.8.4.jar
CVE-2018-1272 spring-core-4.2.0.RELEASE.jar
CVE-2020-5421 spring-web-4.2.0.RELEASE.jar
CVE-2020-11113 jackson-databind-2.8.4.jar
CVE-2022-25647 gson-2.8.2.jar
CVE-2020-11619 jackson-databind-2.8.4.jar
CVE-2023-20863 spring-expression-4.2.0.RELEASE.jar
CVE-2024-22259 spring-web-4.2.0.RELEASE.jar
CVE-2020-24616 jackson-databind-2.8.4.jar
CVE-2020-36184 jackson-databind-2.8.4.jar
CVE-2024-22243 spring-web-4.2.0.RELEASE.jar
CVE-2020-36182 jackson-databind-2.8.4.jar
CVE-2015-5211 spring-webmvc-4.2.0.RELEASE.jar
CVE-2020-25638 hibernate-core-4.3.11.Final.jar
CVE-2020-14061 jackson-databind-2.8.4.jar
CVE-2020-11620 jackson-databind-2.8.4.jar
CVE-2019-14893 jackson-databind-2.8.4.jar
CVE-2024-38809 spring-web-4.2.0.RELEASE.jar
CVE-2020-36189 jackson-databind-2.8.4.jar
CVE-2022-22965 spring-beans-4.2.0.RELEASE.jar
CVE-2018-14720 jackson-databind-2.8.4.jar
CVE-2019-14892 jackson-databind-2.8.4.jar
CVE-2020-36188 jackson-databind-2.8.4.jar
CVE-2021-22096 spring-web-4.2.0.RELEASE.jar
CVE-2016-9878 spring-webmvc-4.2.0.RELEASE.jar
CVE-2020-11111 jackson-databind-2.8.4.jar
CVE-2020-14060 jackson-databind-2.8.4.jar
CVE-2019-14439 jackson-databind-2.8.4.jar
CVE-2018-5968 jackson-databind-2.8.4.jar
CVE-2022-22970 spring-core-4.2.0.RELEASE.jar
CVE-2018-14719 jackson-databind-2.8.4.jar
CVE-2020-36183 jackson-databind-2.8.4.jar
CVE-2019-14379 jackson-databind-2.8.4.jar

Base branch total remaining vulnerabilities: 186
Base branch commit: 80eb1448744dcd3ab7e403f5f4f723c4c6760ae9


Total libraries scanned: 110

Scan token: 43fcfee3da134256bf050121fc80eda2