An open index of dependabot pull requests across open source projects.

org.springframework:spring-webmvc

Ecosystem:
maven
Package URL:
pkg:maven/org.springframework:spring-webmvc
Total PRs:
516 Dependabot PRs
Latest PR:
about 1 month ago
Unique Repositories:
291 repositories
Unique Repos (30 days):
5 repositories
Security Advisories
Path traversal vulnerability in functional web frameworks
GHSA-cx7f-g6mp-7hqm CVE-2024-38816 HIGH published over 1 year ago • updated about 6 hours ago
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An at...
Improper Neutralization of Input During Web Page Generation in Spring Framework
GHSA-ff7p-jqjm-v66h CVE-2014-1904 MODERATE published about 4 years ago • updated about 1 month ago
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 befor...
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
GHSA-6p4f-wcwh-5vvm CVE-2026-22745 MODERATE published about 1 month ago • updated 2 days ago
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application c...
Spring Framework Path Traversal vulnerability
GHSA-g5vr-rgqm-vf78 CVE-2024-38819 HIGH published over 1 year ago • updated 2 days ago
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An at...
Spring Framework MVC Applications Path Traversal Vulnerability
GHSA-r936-gwx5-v52f CVE-2025-41242 MODERATE published 10 months ago • updated 11 days ago
Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An app...
Recent PRs
Bump the maven group across 19 directories with 9 updates

dhay3/spring #3

4.3.9.RELEASE → 4.3.20.RELEASE Patch PR
Closed about 1 month ago 1 comment
dhay3
Package Details
Name: org.springframework:spring-webmvc
Ecosystem: maven
PURL Type: maven
Package URL: pkg:maven/org.springframework:spring-webmvc
JSON API: View JSON
Security Advisories

17

Active advisories
CRITICAL 1
HIGH 6
MODERATE 8
LOW 2
View All maven Advisories
Package Information
Description:

Spring Web MVC

Repository: https://github.com/spring-projects/spring-framework
Homepage: https://github.com/spring-projects/spring-framework
Latest Release: 6.2.7
about 1 year ago
Dependent Repos: 227,195
Dependent Packages: 4,621
Ranking: Top 0.003% by dependent repos Top 0.0156% by dependent pkgs
PR Status
Open 244 (47.3%)
Merged 105 (20.3%)
Closed 138 (26.7%)
PR Types
Major 193 (37.4%)
Minor 30 (5.8%)
Patch 264 (51.2%)