StackRadar

CVE-2026-41850

High

Advisory

Published 9 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
380
of 17,781 indexed, latest versions
Container images
337
deployed by those charts
Fix available
1 of 1
affected package

Spring Framework Algorithmic Denial of Service via SpEL Expressions

Carried by container images the latest versions of 380 of 17,781 indexed charts deploy, on 337 images.

Affected packageAffected versionsFixed inImages
spring-expressionmaven3.2.18.RELEASE, 4.1.1.RELEASE, 4.2.1.RELEASE, 4.3.1.RELEASE+98 more6.2.19, 7.0.8337
OSV records
GHSA-r5w3-xv2f-j59q

Charts affected

380 by stars
ChartLatestAffected imagesRadar Score
pagesbrixton-mayuribhavsar23-pages1.0.01 of 3See more

pages brixton-mayuribhavsar23-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
pagesbrixton-pages1.0.01 of 3See more

pages brixton-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

11,869
pagescamden-pages1.0.01 of 3See more

pages camden-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
camellia-redis-proxycamellia-redis-proxy1.4.01 of 2See more

camellia-redis-proxy camellia-redis-proxy 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
spring-expression@6.2.15
6.2.19

Open the chart page →

8,001
geoservercamptocamp20.0.36 of 12See more

geoserver camptocamp2 0.0.3

6 of the 12 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
spring-expression@5.2.8.RELEASE
no fix listed
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
spring-expression@5.2.8.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
spring-expression@5.2.8.RELEASE
no fix listed
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
spring-expression@5.2.8.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
spring-expression@5.2.8.RELEASE
no fix listed
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
spring-expression@5.2.8.RELEASE
no fix listed

Open the chart page →

88,335
pagescarina-pages1.0.01 of 3See more

pages carina-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
pagescarmel-pages-dell1.0.01 of 3See more

pages carmel-pages-dell 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
Chart-Oracle-Host-Appchart-oracle-host-appVerified publisher0.1.21 of 1See more

Chart-Oracle-Host-App chart-oracle-host-app 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
stanislovesid/oracle-host-app:14fe1ed26e194
spring-expression@5.3.12
no fix listed

Open the chart page →

2,434
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
spring-expression@4.3.8.RELEASE
no fix listed

Open the chart page →

9,808
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
spring-expression@5.3.27
no fix listed

Open the chart page →

6,447
gocdcloudnativeapp1.9.21 of 2See more

gocd cloudnativeapp 1.9.2

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
gocd/gocd-server:v19.3.02da45cb09d57
spring-expression@4.3.22.RELEASE
no fix listed

Open the chart page →

9,144
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
spring-expression@4.3.18.RELEASE
no fix listed

Open the chart page →

23,665
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
spring-expression@5.1.2.RELEASE
no fix listed

Open the chart page →

22,442
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
robotshop/rs-shipping:latest89753ab48919
spring-expression@5.2.8.RELEASE
no fix listed

Open the chart page →

29,555
clusterfactoryclusterfactory0.2.01 of 5See more

clusterfactory clusterfactory 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
spring-expression@6.2.14
6.2.19

Open the chart page →

7,168
gitea-jenkinsclusterfactory0.1.11 of 5See more

gitea-jenkins clusterfactory 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
jenkins/jenkins:2.541.3-jdk21c4098086090c
spring-expression@6.2.14
6.2.19

Open the chart page →

5,238
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
spring-expression@6.2.5
6.2.19

Open the chart page →

4,578
clamapicnieg2.0.51 of 2See more

clamapi cnieg 2.0.5

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
audig/clamapi:2.1.62c3fe34ee430
spring-expression@5.2.8.RELEASE
no fix listed

Open the chart page →

4,671
ganttcnieg2.1.01 of 1See more

gantt cnieg 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
cnieg/gantt:1.1.2d4b478d76f2a
spring-expression@5.3.23
no fix listed

Open the chart page →

2,390
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
spring-expression@5.0.6.RELEASE
no fix listed

Open the chart page →

16,860
consumer-helmconsumer-app-helm-chart0.1.01 of 1See more

consumer-helm consumer-app-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
j4ckhunter/consumer:1.00bb7a429e3e75
spring-expression@5.3.22
no fix listed

Open the chart page →

2,564
pagescrypticcode-helmchart1.0.01 of 3See more

pages crypticcode-helmchart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
spring-expression@5.3.34
no fix listed

Open the chart page →

5,398
pagesdalston-pages1.0.01 of 3See more

pages dalston-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
pagesdaman-dell-kuber1.0.01 of 3See more

pages daman-dell-kuber 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
spring-expression@6.2.10
6.2.19

Open the chart page →

3,547
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
spring-expression@4.3.27.RELEASE
no fix listed

Open the chart page →

8,245
pagesdavid-pages1.0.01 of 3See more

pages david-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
pagesdebasish-pages1.0.01 of 3See more

pages debasish-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.02 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
amartinm82/planner:v2.01184353ff57b
spring-expression@5.3.1
no fix listed
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-expression@5.3.1
no fix listed

Open the chart page →

27,550
pagesdipak1.0.01 of 3See more

pages dipak 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
forwardauthdniel2.0.131 of 1See more

forwardauth dniel 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dniel/forwardauth:latestf67129ea1c64
spring-expression@5.1.8.RELEASE
no fix listed

Open the chart page →

4,592
kafka-uidoubanVerified publisher1.5.21 of 1See more

kafka-ui douban 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-expression@6.2.3
6.2.19

Open the chart page →

1,269
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-expression@5.3.1
no fix listed

Open the chart page →

24,656
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
spring-expression@4.3.24.RELEASE
no fix listed

Open the chart page →

19,802
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
spring-expression@5.3.12
no fix listed

Open the chart page →

2,237
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
spring-expression@6.1.5
no fix listed

Open the chart page →

2,512
management-portaleclipse-aeriosVerified publisher1.1.01 of 2See more

management-portal eclipse-aerios 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
spring-expression@6.1.4
no fix listed

Open the chart page →

3,888
pagesedgwarepages1.0.01 of 3See more

pages edgwarepages 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
spring-expression@5.2.7.RELEASE
no fix listed

Open the chart page →

20,190
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
spring-expression@6.1.21
no fix listed

Open the chart page →

7,268
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
oscarsotosanchez/planner:v1.0730c00a099b8
spring-expression@5.3.1
no fix listed
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-expression@5.3.1
no fix listed

Open the chart page →

27,291
eoloPlanteolo-plannerVerified publisher0.1.01 of 7See more

eoloPlant eolo-planner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
spring-expression@5.3.13
no fix listed

Open the chart page →

27,537
eoloplannereoloplannerVerified publisher0.1.01 of 7See more

eoloplanner eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
spring-expression@5.3.13
no fix listed

Open the chart page →

32,205
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.01 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
spring-expression@5.3.13
no fix listed

Open the chart page →

27,537
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
franrobles8/planner:v3.099985392d63c
spring-expression@5.3.1
no fix listed
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-expression@5.3.1
no fix listed

Open the chart page →

27,256
eoloplannereoloplanner-molynx-gat0.1.01 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
molynx/planner:v1441c9f52f092
spring-expression@5.3.13
no fix listed

Open the chart page →

28,482
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
arturisimo/planner:v1.0fff9de644941
spring-expression@5.3.13
no fix listed

Open the chart page →

27,096
eoloplanteoloplant1.0.01 of 7See more

eoloplant eoloplant 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
spring-expression@5.3.13
no fix listed

Open the chart page →

27,537
eoloplantseoloplants-urjcVerified publisher0.1.01 of 7See more

eoloplants eoloplants-urjc 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41850.

Container imageDigestPackageFixed in
lourdesmorente/new-planner:1.0.0608745878cdb
spring-expression@5.3.13
no fix listed

Open the chart page →

27,721

Container images carrying it

337 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/gla-rad/enav-api-gateway:latest8f4345c77dda
spring-expression@7.0.6
7.0.8
1
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
spring-expression@7.0.7
7.0.8
1
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
spring-expression@7.0.7
7.0.8
1
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
spring-expression@7.0.7
7.0.8
1
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
spring-expression@7.0.6
7.0.8
1
ghcr.io/gla-rad/enav-eureka:latest05002092c621
spring-expression@7.0.6
7.0.8
1
ghcr.io/gla-rad/enav-msg-broker:latest6fe372e4e481
spring-expression@7.0.6
7.0.8
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
spring-expression@7.0.6
7.0.8
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
spring-expression@6.2.14
6.2.19
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
spring-expression@6.2.6
6.2.19
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-expression@6.2.10
6.2.19
1
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
spring-expression@6.2.1
6.2.19
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
spring-expression@5.3.23
no fix listed
1
ghcr.io/jfwenisch/ipfix-generator:latesta1b05567dbf6
spring-expression@6.2.18
6.2.19
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
spring-expression@6.2.0
6.2.19
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
spring-expression@6.2.0
6.2.19
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
spring-expression@5.2.7.RELEASE
no fix listed
1
ghcr.io/kafbat/kafka-ui:v1.2.0185da4ad3e88
spring-expression@6.2.3
6.2.19
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
spring-expression@5.2.6.RELEASE
no fix listed
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
spring-expression@5.3.23
no fix listed
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
spring-expression@6.1.1
no fix listed
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
spring-expression@5.3.31
no fix listed
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-expression@5.1.8.RELEASE
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-expression@5.3.24
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
spring-expression@7.0.7
7.0.8
1
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
spring-expression@6.2.18
6.2.19
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
spring-expression@5.3.16
no fix listed
1
public.ecr.aws/aws-containers/retail-store-sample-cart:1.3.05d767569c976
spring-expression@6.2.10
6.2.19
1
public.ecr.aws/aws-containers/retail-store-sample-orders:1.3.0e85f034bcf48
spring-expression@6.2.10
6.2.19
1
public.ecr.aws/aws-containers/retail-store-sample-ui:1.3.0ce3f2e935eb3
spring-expression@6.2.10
6.2.19
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
spring-expression@5.3.24
no fix listed
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-expression@6.1.1
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
spring-expression@6.1.3
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
spring-expression@6.1.3
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
spring-expression@6.1.3
no fix listed
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
spring-expression@5.3.31
no fix listed
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
spring-expression@5.3.7
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.