Visitar URL original
[GHSA-549f-4rpc-3rw9] Spring MVC and WebFlux applications that obtain a data... by ranjiGT · Pull Request #10232 · github/advisory-database · GitHub
Skip to content

[GHSA-549f-4rpc-3rw9] Spring MVC and WebFlux applications that obtain a data... - #10232

Open
ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10232from
ranjiGT-GHSA-549f-4rpc-3rw9
Open

ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10232from
ranjiGT-GHSA-549f-4rpc-3rw9

Conversation

@ranjiGT

@ranjiGT ranjiGT commented Oct 8, 2026

Copy link
Copy Markdown

Updates

  • Affected products
  • Description
  • References
  • Source code location
  • Summary

Comments

Reason for Change

This contribution improves the accuracy and completeness of
GHSA-549f-4rpc-3rw9 (CVE-2026-59281) by adding:

  • The affected Maven package: org.springframework:spring-web.
  • Affected version ranges across six Spring Framework release branches.
  • Documented fixed versions and their availability.
  • The upstream source repository.
  • References to the upstream issue, security fix commits, and release.

Technical Details

The vulnerability originates in the spring-web module, specifically:

org.springframework.web.bind.EscapedErrors

The no-argument getFieldErrors() and getFieldError() methods previously
returned field errors without consistently applying HTML escaping.

The upstream fix updates these methods to use the existing escaping
helpers and introduces regression tests covering HTML escaping of
rejected values and error messages.

Upstream Verification

Version Mapping

The affected version ranges follow the official Spring security advisory.

Spring Framework 7.0.9 is the documented open-source fixed release.
The fixes for older supported branches are designated
Enterprise Support Only by Spring.

The 5.2.x-and-earlier affected-product entry intentionally leaves the
patched Maven version unspecified because the exact enterprise artifact
version has not been independently verified.

Expected Improvement

These changes provide more complete package and version metadata
for vulnerability identification, dependency scanning, and
security advisory tracking.

Copilot AI balanced review requested due to automatic review settings October 8, 2026 18:24
@github-actions
github-actions Bot changed the base branch from main to ranjiGT/advisory-improvement-10232 October 8, 2026 18:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Four enterprise-only versions are incorrectly used as public Maven fixed-version boundaries.

0 open findings

What changed in this PR

Improves GHSA-549f-4rpc-3rw9 with Spring Framework package, version, remediation, and source metadata.

Changes:

  • Adds affected Maven ranges and fixed-version guidance.
  • Adds upstream issue, commits, repository, and release references.
  • Expands the summary and vulnerability details.
File Description
advisories/​unreviewed/​2026/​08/​GHSA-549f-4rpc-3rw9/​GHSA-549f-4rpc-3rw9.json Enriches the Spring Framework advisory metadata.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants