CVE-2026-22741
LowAdvisory
Published 29 Apr 2026In the index since 5 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 3.1
- base score, highest
- EPSS
- 0.002
- 15th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 310
- of 17,787 indexed, latest versions
- Container images
- 268
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
Carried by container images the latest versions of 310 of 17,787 indexed charts deploy, on 268 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| spring-webmvcmaven | 2.5.6.SEC03, 3.2.18.RELEASE, 4.3.1.RELEASE, 4.3.2.RELEASE+85 more | 6.2.18, 7.0.7 | 241 |
| spring-webfluxmaven | 5.2.2.RELEASE, 5.2.7.RELEASE, 5.2.8.RELEASE, 5.3.1+27 more | 6.2.18, 7.0.7 | 67 |
- OSV records
- GHSA-wg35-8jpf-2xv3
Charts affected
310 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| timetabletwomartensVerified publisher | 0.2.0 | 1 of 1See more | 1,527 |
| wahlrechttwomartensVerified publisher | 0.3.0 | 1 of 1See more | 1,689 |
| pagesvictor-pages | 1.0.0 | 1 of 3See more | 20,190 |
| kube-monitoring-telegram-botviento-repository | 1.0.0 | 1 of 1See more | 7,885 |
| pageswalter | 1.0.0 | 1 of 3See more | 20,190 |
| webapp-db-javawebapp-db-java-repo | 0.1.0 | 1 of 2See more | 2,566 |
| webhookiewebhookie | 0.1.2 | 1 of 1See more | 14,364 |
| webhookie-allwebhookie | 0.1.2 | 1 of 3See more | 28,605 |
| workshop-pipelinesworkshop-pipelines | 0.1.6 | 1 of 2See more | 11,577 |
| zahori-serverzahoriVerified publisher | 1.0.1 | 1 of 2See more | 5,846 |
Container images carrying it
268 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.