If you think you have found a security vulnerability, please DO NOT disclose it publicly until we’ve had a chance to fix it. Please don’t report security vulnerabilities using GitHub issues, instead head over to https://spring.io/security-policy and learn how to disclose them responsibly.
Security: spring-projects/security-advisories
Security
SECURITY.md
-
Unbounded property-path cache keyed by externally-supplied path stringGHSA-88fw-v6x4-3f58 published
Jun 9, 2026 by mp911deHigh
Learn more about advisories related to spring-projects/security-advisories in the GitHub Advisory Database