An open index of dependabot pull requests across open source projects.

org.springframework:spring-web

Ecosystem:
maven
Package URL:
pkg:maven/org.springframework:spring-web
Total PRs:
939 Dependabot PRs
Latest PR:
about 1 month ago
Unique Repositories:
459 repositories
Unique Repos (30 days):
3 repositories
Security Advisories
Spring Framework Cross Site Tracing (XST)
GHSA-9gcm-f4x3-8jpw CVE-2018-11039 MODERATE published over 7 years ago • updated about 2 hours ago
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change t...
Cross-Site Request Forgery in Spring Framework
GHSA-g6hf-f9cq-q7w7 CVE-2013-6429 MODERATE published about 4 years ago • updated about 4 hours ago
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resol...
Spring Framework vulnerable to a reflected file download (RFD)
GHSA-6r3c-xf4w-jxjm CVE-2025-41234 MODERATE published about 1 year ago • updated about 1 hour ago
### Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file downlo...
Spring Web vulnerable to Open Redirect or Server Side Request Forgery
GHSA-ccgv-vj62-xf9h CVE-2024-22243 HIGH published over 2 years ago • updated about 1 hour ago
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on th...
Pivotal Spring Framework contains unsafe Java deserialization methods
GHSA-4wrc-f8pq-fpqp CVE-2016-1000027 CRITICAL published about 4 years ago • updated about 2 hours ago
Pivotal Spring Framework before 6.0.0 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data...
Recent PRs
Package Details
Name: org.springframework:spring-web
Ecosystem: maven
PURL Type: maven
Package URL: pkg:maven/org.springframework:spring-web
JSON API: View JSON
Security Advisories

12

Active advisories
CRITICAL 1
HIGH 4
MODERATE 7
View All maven Advisories
Package Information
Description:

Spring Web

Repository: https://github.com/spring-projects/spring-framework
Homepage: https://github.com/spring-projects/spring-framework
Latest Release: 6.2.7
about 1 year ago
Dependent Repos: 153,377
Dependent Packages: 6,673
Ranking: Top 0.0054% by dependent repos Top 0.0092% by dependent pkgs
PR Status
Open 408 (43.5%)
Merged 186 (19.8%)
Closed 267 (28.4%)
PR Types
Major 275 (29.3%)
Minor 62 (6.6%)
Patch 524 (55.8%)