Skip to content

[Aikido] Fix 36 security issues in jackson-core, spring-data-commons, spring-boot and 9 more - #21

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-106774343-cgi1
Open

[Aikido] Fix 36 security issues in jackson-core, spring-data-commons, spring-boot and 9 more#21
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-106774343-cgi1

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Sep 6, 2026

Copy link
Copy Markdown

Upgrade dependencies to fix critical RCE, authentication bypass, and input validation vulnerabilities in Tomcat and Spring frameworks.

⚠️ Breaking changes analysis not available for: org.springframework.data:spring-data-commons, org.springframework.boot:spring-boot, org.springframework.boot:spring-boot-dependencies, org.springframework.boot:spring-boot-loader

✅ No breaking changes for: com.fasterxml.jackson.core:jackson-core, com.fasterxml.jackson.core:jackson-databind, org.springframework:spring-core, org.springframework:spring-webmvc, org.springframework:spring-web, org.springframework:spring-beans, org.springframework:spring-expression, org.springframework:spring-context

✅ 68 CVEs resolved by this upgrade, including 7 critical 🚨 CVEs

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2025-24813
🚨 CRITICAL
[tomcat-embed-core] Path traversal vulnerability in the Default Servlet with write permissions enabled allows remote code execution, information disclosure, or malicious file injection through partial PUT requests exploiting internal dot path equivalence.
CVE-2026-41293
🚨 CRITICAL
[tomcat-embed-core] Improper input validation vulnerability allows attackers to bypass security controls or trigger unexpected behavior. Potential impacts include remote code execution, denial of service, or information disclosure depending on exploitation context.
CVE-2026-43512
🚨 CRITICAL
[tomcat-embed-core] Digest authentication bypass vulnerability allowing attackers to bypass authentication mechanisms and gain unauthorized access to protected resources.
CVE-2024-50379
🚨 CRITICAL
[tomcat-embed-core] TOCTOU race condition in JSP compilation on case-insensitive filesystems with writable default servlet allows remote code execution. Affects multiple versions when non-default write permissions are enabled.
CVE-2025-31651
🚨 CRITICAL
[tomcat-embed-core] Improper neutralization of escape sequences in rewrite rules allows specially crafted requests to bypass security constraints under specific configurations. This could lead to unauthorized access if rewrite rules enforce security policies.
CVE-2025-55754
🚨 CRITICAL
[tomcat-embed-core] Improper neutralization of ANSI escape sequences in log messages allows attackers to inject sequences via crafted URLs to manipulate console output and clipboard on Windows systems, potentially tricking administrators into executing malicious commands.
CVE-2026-43515
🚨 CRITICAL
[tomcat-embed-core] Improper authorization in method constraints allows attackers to bypass HTTP method restrictions on specific file extensions, potentially enabling unauthorized access to protected resources.
CVE-2026-65905
HIGH
[tomcat-embed-core] DIGEST authentication replay window boundary condition allows a single replay of authenticated requests, enabling authentication bypass through capture-replay attacks.
CVE-2025-66614
HIGH
[tomcat-embed-core] Improper validation of SNI extension hostname against HTTP host header allows clients to bypass client certificate authentication by providing mismatched hostnames across multiple virtual hosts. This enables authentication bypass when certificate requirements differ between virtual hosts.
CVE-2026-65182
HIGH
[tomcat-embed-core] Security constraint bypass vulnerability where longer path constraints specified before shorter sub-path constraints allow unauthorized access. This improper access control flaw enables attackers to bypass security restrictions.
CVE-2026-68525
HIGH
[tomcat-embed-core] FORM authentication incorrectly authorizes requests, allowing attackers to bypass security constraints by accessing resources via GET that should only permit POST, enabling unauthorized access.
CVE-2025-48988
HIGH
[tomcat-embed-core] Uncontrolled resource allocation vulnerability allowing attackers to exhaust server resources without limits, leading to denial of service attacks.
CVE-2025-55752
HIGH
[tomcat-embed-core] Relative path traversal vulnerability in URL rewriting allows attackers to bypass security constraints for /WEB-INF/ and /META-INF/, potentially enabling remote code execution if PUT requests are enabled.
CVE-2026-24880
HIGH
[tomcat-embed-core] HTTP request smuggling vulnerability via invalid chunk extensions allows attackers to bypass security controls and potentially execute arbitrary code or manipulate request handling.
CVE-2025-31650
HIGH
[tomcat-embed-core] Improper validation of invalid HTTP priority headers causes incomplete request cleanup, leading to memory leaks. Repeated malicious requests can trigger OutOfMemoryException, causing denial of service.
CVE-2024-56337
HIGH
[tomcat-embed-core] A TOCTOU race condition in the default servlet on case-insensitive file systems with write enabled allows attackers to bypass security checks and potentially execute arbitrary code or access unauthorized files.
CVE-2025-55668
MEDIUM
[tomcat-embed-core] Session fixation vulnerability in the rewrite valve allows attackers to hijack user sessions by reusing existing session identifiers, potentially leading to unauthorized access.
CVE-2025-48989
MEDIUM
[tomcat-embed-core] Improper resource shutdown vulnerability allows attackers to exploit the "made you reset" attack, potentially causing denial of service or connection manipulation through incomplete resource cleanup.
CVE-2025-52520
MEDIUM
[tomcat-embed-core] Integer overflow in multipart upload handling allows bypassing size limits, leading to denial of service in specific configurations.
CVE-2026-24734
MEDIUM
[tomcat-embed-core] Improper input validation in OCSP responder handling fails to verify response freshness and completion, allowing certificate revocation to be bypassed. This enables attackers to use revoked certificates for authentication or encryption.
CVE-2026-34483
MEDIUM
[tomcat-embed-core] Improper output encoding in JsonAccessLogValve allows injection of malicious content into access logs, potentially enabling log manipulation and code injection attacks.
CVE-2026-34487
MEDIUM
[tomcat-embed-core] Cloud membership clustering component logs Kubernetes bearer tokens, exposing sensitive authentication credentials through log files.
CVE-2026-41284
MEDIUM
[tomcat-embed-core] Uncontrolled resource allocation vulnerability allows attackers to exhaust server resources through unlimited allocation requests, leading to denial of service.
CVE-2026-43513
MEDIUM
[tomcat-embed-core] Improper handling of case sensitivity in LockOutRealm allows attackers to bypass account lockout protections through case-variant username manipulation.
CVE-2025-49125
MEDIUM
[tomcat-embed-core] Authentication bypass vulnerability allowing access to PreResources/PostResources via alternate paths, bypassing security constraints that protect the expected paths.
CVE-2026-42498
MEDIUM
[tomcat-embed-core] HTTP Authentication headers are exposed to unexpected hosts during WebSocket authentication, allowing potential credential disclosure to unauthorized parties.
CVE-2026-25854
MEDIUM
[tomcat-embed-core] Open redirect vulnerability in LoadBalancerDrainingValve allows attackers to redirect users to untrusted sites. This could enable phishing attacks or malicious redirects to compromise user security.
CVE-2025-61795
MEDIUM
[tomcat-embed-core] Temporary files from multipart uploads aren't cleaned up immediately during errors, allowing disk space to fill faster than garbage collection clears it, causing denial of service.
CVE-2025-49124
LOW
[tomcat-embed-core] Untrusted search path vulnerability in Windows installer allows arbitrary code execution when icacls.exe is invoked without a full path, enabling attackers to execute malicious code during installation.
CVE-2025-53506
LOW
[tomcat-embed-core] An HTTP/2 client that fails to acknowledge initial settings frame can cause uncontrolled resource consumption by bypassing concurrent stream limits. This leads to potential denial of service through resource exhaustion.
CVE-2026-43514
LOW
[tomcat-embed-core] Observable timing discrepancy in AJP secret comparison allows attackers to bypass authentication through timing analysis attacks.
CVE-2025-46701
LOW
[tomcat-embed-core] Improper case sensitivity handling in CGI servlet allows bypass of security constraints applied to URI path components. This enables attackers to circumvent access controls.
GHSA-r7wm-3cxj-wff9
HIGH
[jackson-core] Incomplete fix for number length validation in async parser allows attackers to bypass constraints by streaming JSON without terminators, causing unbounded memory accumulation up to 20 MiB per connection (~20,000x amplification of the configured limit). This enables denial-of-service through memory exhaustion in reactive frameworks.
CVE-2026-18401
MEDIUM
[jackson-core] The async JSON parser fails to enforce the maxNumberLength constraint, allowing attackers to submit arbitrarily long number tokens causing excessive memory allocation and CPU exhaustion (DoS). The synchronous parser correctly enforces this limit, creating an inconsistency in constraint validation between parsing APIs.
AIKIDO-2026-11184
HIGH
[spring-data-commons] A property-lookup cache accepts attacker-supplied strings as permanent cache keys, enabling heap exhaustion denial-of-service attacks through repeated requests. Vulnerable applications use Querydsl web bindings or @ProjectedPayload form-parameter binding that forward unfiltered HTTP-supplied strings to PropertyPath.from.
AIKIDO-2026-11186
LOW
[spring-data-commons] Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution.
AIKIDO-2026-11183
LOW
[spring-data-commons] A vulnerability in Spring Data Web Support with @ProjectedPayload allows attackers to trigger excessive memory allocation through specially crafted HTTP requests, causing Denial of Service.
AIKIDO-2026-11185
LOW
[spring-data-commons] Malicious Sort parameters can cause a StackOverflowException, leading to Denial of Service when endpoints accept untrusted Sort input or use @ProjectedPayload/@QuerydslPredicate annotations without sanitization.
CVE-2025-22235
HIGH
[spring-boot] EndpointRequest.to() incorrectly creates a matcher for null/** when the referenced actuator endpoint is disabled or not exposed, potentially allowing unauthorized access to /null paths that should be protected by Spring Security.
AIKIDO-2026-10660
HIGH
[spring-boot] Insecure temporary directory handling allows a local attacker to predict and take control of temp directories without ownership verification. This enables session hijacking or remote code execution when persistent sessions are enabled.
AIKIDO-2026-10581
MEDIUM
[spring-boot] ApplicationPidFileWriter improperly follows symlinks when writing PID files at predictable paths, allowing local attackers with write access to cause arbitrary file corruption on application startup.
AIKIDO-2026-10583
MEDIUM
[spring-boot] A weak pseudo-random number generator is used for ${random.value}, generating predictable values unsuitable for secrets. This can weaken tokens, passwords, and other security-sensitive data derived from these properties.
CVE-2026-40973
MEDIUM
[spring-boot] A local attacker can hijack the predictable temporary directory used by ApplicationTemp, potentially reading session data to hijack authenticated users or executing arbitrary code through gadget chain deployment when persistent sessions are enabled.
CVE-2026-54512
HIGH
[jackson-databind] Polymorphic type validator bypass allows attackers to deserialize denied classes by hiding them as generic type parameters within allowed container types. This enables remote code execution through instantiation and property population of malicious gadget classes.
CVE-2026-54513
HIGH
[jackson-databind] BasicPolymorphicTypeValidator's allowIfSubTypeIsArray() method fails to validate array component types against the allowlist, allowing deserialization of non-allowlisted types as array elements. This bypasses type validation and enables remote code execution through malicious object instantiation.
CVE-2026-59888
MEDIUM
[jackson-databind] A PropertyNamingStrategy bypass allows @JsonIgnore annotations to be circumvented on Java Records, enabling ignored fields to be populated via renamed JSON keys during deserialization.
CVE-2026-54514
MEDIUM
[jackson-databind] Unsafe DNS resolution occurs when deserializing InetSocketAddress objects from untrusted JSON, allowing attackers to trigger arbitrary DNS queries before application validation. This enables DNS-based attacks and information disclosure through the deserialization process.
AIKIDO-2026-11158
HIGH
[spring-core] Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability.
CVE-2025-41249
MEDIUM
[spring-core] Annotation detection mechanism fails to correctly resolve security annotations on methods in type hierarchies with parameterized supertypes containing unbounded generics, potentially bypassing authorization decisions in Spring Security's @EnableMethodSecurity feature.
CVE-2026-41851
MEDIUM
[spring-core] SpEL expression evaluation can trigger unbounded cache growth, leading to Denial of Service when processing user-supplied expressions. An attacker can exhaust memory resources by crafting malicious SpEL expressions that cause excessive cache accumulation.
CVE-2025-41242
MEDIUM
[spring-core] A path traversal vulnerability in Spring Framework MVC applications allows attackers to access files outside intended directories when deployed on non-compliant Servlet containers that don't reject suspicious URI sequences and serve static resources through Spring resource handling.
CVE-2025-41234
MEDIUM
[spring-core] A reflected file download (RFD) vulnerability exists when ContentDisposition.Builder#filename() with non-ASCII charset uses unsanitized user input, allowing attackers to inject malicious commands into downloaded content. Proper input sanitization or using ASCII charset mitigates this risk.
CVE-2026-41854
MEDIUM
[spring-core] Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.

Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
CVE-2026-41845
MEDIUM
[spring-core] Incorrect escaping in JavaScriptUtils.javaScriptEscape() allows JavaScript code injection in the browser, leading to cross-site scripting (XSS) vulnerabilities.
CVE-2026-41844
MEDIUM
[spring-core] An attacker can craft a malicious link using the "redirect:" prefix to perform an open redirect to an arbitrary external host in applications with a "/**" mapping lacking explicit view name specification. This enables phishing attacks and credential theft through unvalidated redirects.
CVE-2026-41846
MEDIUM
[spring-core] JSP form tags fail to properly sanitize user-supplied values in cssClass, cssErrorClass, and cssStyle attributes, allowing arbitrary HTML/JavaScript injection and cross-site scripting (XSS) attacks.
CVE-2026-22737
MEDIUM
[spring-core] A path traversal vulnerability in Java scripting engine template views allows attackers to read arbitrary files outside configured template directories, resulting in information disclosure.
CVE-2026-41841
MEDIUM
[spring-core] Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources.

Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
CVE-2026-41843
MEDIUM
[spring-core] Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources.

Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
CVE-2026-41852
MEDIUM
[spring-core] SpEL evaluation logic allows arbitrary zero-argument method invocation in restricted contexts, enabling attackers to invoke unintended application logic and potentially execute remote code or bypass security restrictions.
CVE-2026-41853
MEDIUM
[spring-core] Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.

Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
CVE-2026-41848
LOW
[spring-core] A Regular Expression Denial of Service (ReDoS) vulnerability exists in AntPathMatcher methods that process user-supplied patterns, allowing attackers to cause application hangs or crashes through malicious regex patterns.
CVE-2026-41850
LOW
[spring-core] SpEL expression evaluation is vulnerable to Algorithmic Denial of Service (DoS) when processing specially crafted user-supplied expressions, causing excessive resource consumption and potential application unavailability.
CVE-2026-41842
LOW
[spring-core] Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.

Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
CVE-2025-22233
LOW
[spring-core] A bypass vulnerability exists in disallowedFields validation that allows attackers to circumvent field binding restrictions through locale-dependent case conversion, potentially enabling unauthorized data binding and remote code execution.
CVE-2026-22741
LOW
[spring-core] Cache poisoning vulnerability in static resource resolution allows attackers to poison the resource cache with incorrectly encoded resources, causing denial of service and breaking front-end applications for clients.
CVE-2026-22745
LOW
[spring-core] Spring MVC and WebFlux applications serving static resources on Windows are vulnerable to Denial of Service attacks through malicious requests that consume HTTP connections and slow resource resolution.
CVE-2026-22735
LOW
[spring-core] Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
🔗 Related Tasks
🤖 Remediation details

Fix transitive security vulnerabilities via Spring Boot parent POM upgrade (demos/archunit-guardrails)

This PR remediates security vulnerabilities in Apache Tomcat, Spring Boot, Spring Framework, Spring Data Commons, jackson-core, and jackson-databind as pulled in transitively through the spring-boot-starter-parent BOM in demos/archunit-guardrails/pom.xml. All fixes are achieved by bumping the parent POM version and adding one property override — no direct dependency declarations were added or removed.

Apache Tomcat

Tomcat (tomcat-embed-core and siblings) is resolved transitively via spring-boot-starter-parent. The parent was bumped from 3.4.0 to 3.5.16, which raises the managed Tomcat version from 10.1.33 to 10.1.55, addressing the bulk of the Tomcat CVE set. However, three CVEs (CVE-2026-65905, CVE-2026-65182, CVE-2026-68525) require Tomcat ≥ 10.1.58 on the 10.1.x branch; since 10.1.58 was never published (the release sequence skips to 10.1.59), a <tomcat.version>10.1.59</tomcat.version> property override was added to <properties>. Spring Boot's BOM uses this property for all Tomcat artifacts, so the single override lifts the entire Tomcat family to 10.1.59 without any dependencyManagement entries.

Spring Boot

spring-boot and its starter artifacts are direct dependencies (via spring-boot-starter-web, spring-boot-starter-data-jpa, spring-boot-starter-test) whose versions are governed entirely by the parent POM. Bumping spring-boot-starter-parent from 3.4.0 to 3.5.16 resolves spring-boot itself to 3.5.16, satisfying the ≥ 3.5.14 patched-version floor required by CVE-2025-22235, AIKIDO-2026-10660, AIKIDO-2026-10581, AIKIDO-2026-10583, and CVE-2026-40973.

Spring Framework (spring-web, spring-core, spring-webmvc, spring-beans, spring-expression, spring-context)

All Spring Framework artifacts are resolved transitively through the spring-framework-bom imported by spring-boot-dependencies. The parent bump to 3.5.16 causes the BOM to manage Spring Framework at 6.2.19, meeting the ≥ 6.2.19 floor required across the full set of Spring Framework CVEs (CVE-2026-41841 through CVE-2026-41854, CVE-2026-22735/22737/22741/22745, CVE-2025-41234/41242/41249, CVE-2025-22233, AIKIDO-2026-11158, and others).

Spring Data Commons

spring-data-commons is resolved transitively via spring-boot-starter-data-jpaspring-data-bom, which is imported by spring-boot-dependencies. The parent bump to 3.5.16 updates the managed spring-data-bom version to 2025.0.13, resolving spring-data-commons to 3.5.13 — above the ≥ 3.5.12 floor required by AIKIDO-2026-11183, AIKIDO-2026-11184, AIKIDO-2026-11185, and AIKIDO-2026-11186.

com.fasterxml.jackson.core:jackson-core

jackson-core is resolved transitively through spring-boot-starter-webjackson-bom, managed by spring-boot-dependencies. The parent bump to 3.5.16 sets jackson-bom.version to 2.21.4, which resolves jackson-core to 2.21.4 — well above the ≥ 2.18.8 patched-version floor required by GHSA-r7wm-3cxj-wff9 and CVE-2026-18401.

com.fasterxml.jackson.core:jackson-databind

jackson-databind is co-managed with jackson-core under the same jackson-bom imported by spring-boot-dependencies. The parent bump to 3.5.16 resolves jackson-databind to 2.21.4 via the same BOM update, satisfying the ≥ 2.18.8 floor required by CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, and CVE-2026-59888.

Version changes

Package From To Why updated
org.springframework.boot:spring-boot-starter-parent (parent POM) 3.4.0 3.5.16 Direct parent bump — root fix driving all transitive upgrades
org.springframework.boot:spring-boot 3.4.0 3.5.16 Transitive after parent bump to spring-boot-starter-parent:3.5.16
org.springframework:spring-web 6.2.0 6.2.19 Transitive after parent bump to spring-boot-starter-parent:3.5.16
org.springframework:spring-webmvc 6.2.0 6.2.19 Transitive after parent bump to spring-boot-starter-parent:3.5.16
org.springframework:spring-core 6.2.0 6.2.19 Transitive after parent bump to spring-boot-starter-parent:3.5.16
org.springframework:spring-beans 6.2.0 6.2.19 Transitive after parent bump to spring-boot-starter-parent:3.5.16
org.springframework:spring-context 6.2.0 6.2.19 Transitive after parent bump to spring-boot-starter-parent:3.5.16
org.springframework:spring-expression 6.2.0 6.2.19 Transitive after parent bump to spring-boot-starter-parent:3.5.16
org.springframework.data:spring-data-commons 3.4.0 3.5.13 Transitive after parent bump to spring-boot-starter-parent:3.5.16
com.fasterxml.jackson.core:jackson-core 2.18.1 2.21.4 Transitive after parent bump to spring-boot-starter-parent:3.5.16
com.fasterxml.jackson.core:jackson-databind 2.18.1 2.21.4 Transitive after parent bump to spring-boot-starter-parent:3.5.16
org.apache.tomcat.embed:tomcat-embed-core (and Tomcat siblings) 10.1.33 10.1.59 Transitive after parent bump + tomcat.version property override to 10.1.59

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants