Skip to content

[Snyk] Fix for 56 vulnerabilities#16

Open
snyk-io[bot] wants to merge 1 commit intomainfrom
snyk-fix-c79f1ddf20b67e3320f2a75b4b0f9d24
Open

[Snyk] Fix for 56 vulnerabilities#16
snyk-io[bot] wants to merge 1 commit intomainfrom
snyk-fix-c79f1ddf20b67e3320f2a75b4b0f9d24

Conversation

@snyk-io
Copy link

@snyk-io snyk-io bot commented Mar 7, 2026

snyk-top-banner

Snyk has created this PR to fix 56 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • fractalx-runtime/pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Score Upgrade
high severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924
  828   Major version upgrade Proof of Concept
high severity Improper Cleanup on Thrown Exception
SNYK-JAVA-ORGAPACHETOMCATEMBED-9905132
  821   Mature
high severity Path Equivalence
SNYK-JAVA-ORGAPACHETOMCATEMBED-9396739
  814   Mature
critical severity Uncaught Exception
SNYK-JAVA-ORGAPACHETOMCATEMBED-8383920
  781   Proof of Concept
critical severity Time-of-check Time-of-use (TOCTOU) Race Condition
SNYK-JAVA-ORGAPACHETOMCATEMBED-8523186
  781   Proof of Concept
critical severity Time-of-check Time-of-use (TOCTOU) Race Condition
SNYK-JAVA-ORGAPACHETOMCATEMBED-8547999
  781   Proof of Concept
high severity Path Traversal
SNYK-JAVA-ORGSPRINGFRAMEWORK-7945490
  756   Proof of Concept
high severity Path Traversal
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230373
  756   Proof of Concept
high severity Relative Path Traversal
SNYK-JAVA-ORGAPACHETOMCATEMBED-13733966
  706   Proof of Concept
high severity Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-6435948
  696   Proof of Concept
high severity Infinite loop
SNYK-JAVA-ORGBOUNCYCASTLE-6612984
  696   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
Proof of Concept
high severity Open Redirect
SNYK-JAVA-ORGSPRINGFRAMEWORK-6261586
  676   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
Proof of Concept
high severity Improper Certificate Validation
SNYK-JAVA-ORGAPACHETOMCATEMBED-15307781
  666   No Known Exploit
critical severity Authentication Bypass by Primary Weakness
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-9486467
  664   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
No Known Exploit
high severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-COMMONSFILEUPLOAD-10363252
  649   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
No Known Exploit
high severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGAPACHETOMCATEMBED-10365122
  649   No Known Exploit
high severity Integer Overflow or Wraparound
SNYK-JAVA-ORGAPACHETOMCATEMBED-10674391
  649   No Known Exploit
high severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGAPACHETOMCATEMBED-10676855
  649   No Known Exploit
high severity Improper Resource Shutdown or Release
SNYK-JAVA-ORGAPACHETOMCATEMBED-11799152
  649   No Known Exploit
high severity Insufficient Session Expiration
SNYK-JAVA-ORGAPACHETOMCATEMBED-7430175
  649   No Known Exploit
high severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGAPACHETOMCATEMBED-8073090
  649   No Known Exploit
high severity Incorrect Authorization
SNYK-JAVA-ORGSPRINGFRAMEWORK-12817817
  649   No Known Exploit
high severity Incorrect Authorization
SNYK-JAVA-ORGAPACHETOMCATEMBED-15307822
  641   No Known Exploit
medium severity Improper Neutralization
SNYK-JAVA-ORGAPACHETOMCATEMBED-9905136
  636   Proof of Concept
high severity Relative Path Traversal
SNYK-JAVA-ORGSPRINGFRAMEWORK-12008931
  624   No Known Exploit
medium severity Observable Discrepancy
SNYK-JAVA-ORGBOUNCYCASTLE-6613076
  616   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
Proof of Concept
medium severity Open Redirect
SNYK-JAVA-ORGSPRINGFRAMEWORK-6597980
  591   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
Proof of Concept
high severity Untrusted Search Path
SNYK-JAVA-ORGAPACHETOMCATEMBED-13746602
  589   No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-ORGAPACHETOMCATEMBED-6435950
  589   No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-CHQOSLOGBACK-6094942
  569   No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-CHQOSLOGBACK-6094943
  569   No Known Exploit
high severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JAVA-CHQOSLOGBACK-6097492
  569   No Known Exploit
high severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JAVA-CHQOSLOGBACK-6097493
  569   No Known Exploit
high severity Open Redirect
SNYK-JAVA-ORGSPRINGFRAMEWORK-6444790
  569   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
No Known Exploit
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JAVA-COMMONSIO-8161190
  559   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
No Known Exploit
medium severity Session Fixation
SNYK-JAVA-ORGAPACHETOMCATEMBED-11798986
  559   No Known Exploit
medium severity Denial of Service (DoS)
SNYK-JAVA-ORGSPRINGFRAMEWORK-7687447
  559   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
No Known Exploit
medium severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGAPACHETOMCATEMBED-10264469
  529   No Known Exploit
medium severity Authentication Bypass Using an Alternate Path or Channel
SNYK-JAVA-ORGAPACHETOMCATEMBED-10365310
  529   No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGBOUNCYCASTLE-11777846
  529   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGBOUNCYCASTLE-11789695
  529   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
No Known Exploit
medium severity Authorization Bypass
SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-8399273
  529   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
No Known Exploit
medium severity Improper Resource Shutdown or Release
SNYK-JAVA-ORGAPACHETOMCATEMBED-13723930
  514   No Known Exploit
medium severity External Initialization of Trusted Variables or Data Stores
SNYK-JAVA-CHQOSLOGBACK-13169722
  509   No Known Exploit
medium severity Improper Neutralization of Special Elements
SNYK-JAVA-CHQOSLOGBACK-8539866
  509   No Known Exploit
medium severity Improper Neutralization of Special Elements
SNYK-JAVA-CHQOSLOGBACK-8539867
  509   No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGBOUNCYCASTLE-6613079
  479   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
No Known Exploit
medium severity HTTP Response Splitting
SNYK-JAVA-ORGSPRINGFRAMEWORK-10345766
  439   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
No Known Exploit
low severity Improper Authorization
SNYK-JAVA-ORGAPACHETOMCATEMBED-15307825
  401   No Known Exploit
low severity Server-side Request Forgery (SSRF)
SNYK-JAVA-CHQOSLOGBACK-8539865
  334   No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-10176071
  329   No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230364
  329   No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230365
  329   No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230366
  329   org.springframework.cloud:spring-cloud-starter-openfeign:
4.1.0 -> 4.2.0
No Known Exploit
low severity Improper Handling of Case Sensitivity
SNYK-JAVA-ORGSPRINGFRAMEWORK-8230368
  329   No Known Exploit
low severity External Initialization of Trusted Variables or Data Stores
SNYK-JAVA-CHQOSLOGBACK-15062482
  304   No Known Exploit

Vulnerabilities that could not be fixed

  • Upgrade:
    • Could not upgrade org.springframework.boot:spring-boot-starter-aop@3.2.0 to org.springframework.boot:spring-boot-starter-aop@3.4.10; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/3.2.0/spring-boot-dependencies-3.2.0.pom
  • Could not upgrade org.springframework.boot:spring-boot-starter-web@3.2.0 to org.springframework.boot:spring-boot-starter-web@4.0.0; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/3.2.0/spring-boot-dependencies-3.2.0.pom

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Denial of Service (DoS)
🦉 Server-side Request Forgery (SSRF)
🦉 Allocation of Resources Without Limits or Throttling
🦉 More lessons are available in Snyk Learn

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-9905132
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-9396739
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-8383920
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-8523186
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-8547999
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-7945490
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-8230373
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-13733966
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-6435948
- https://snyk.io/vuln/SNYK-JAVA-ORGBOUNCYCASTLE-6612984
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-6261586
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-15307781
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-9486467
- https://snyk.io/vuln/SNYK-JAVA-COMMONSFILEUPLOAD-10363252
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-10365122
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-10674391
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-10676855
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-11799152
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-7430175
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-8073090
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-12817817
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-15307822
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-9905136
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-12008931
- https://snyk.io/vuln/SNYK-JAVA-ORGBOUNCYCASTLE-6613076
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-6597980
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-13746602
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-6435950
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-6094942
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-6094943
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-6097492
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-6097493
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-6444790
- https://snyk.io/vuln/SNYK-JAVA-COMMONSIO-8161190
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-11798986
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-7687447
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-10264469
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-10365310
- https://snyk.io/vuln/SNYK-JAVA-ORGBOUNCYCASTLE-11777846
- https://snyk.io/vuln/SNYK-JAVA-ORGBOUNCYCASTLE-11789695
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-8399273
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-13723930
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-13169722
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-8539866
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-8539867
- https://snyk.io/vuln/SNYK-JAVA-ORGBOUNCYCASTLE-6613079
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-10345766
- https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-15307825
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-8539865
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-10176071
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-8230364
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-8230365
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-8230366
- https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-8230368
- https://snyk.io/vuln/SNYK-JAVA-CHQOSLOGBACK-15062482
@snyk-io
Copy link
Author

snyk-io bot commented Mar 7, 2026

Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@sonarqubecloud
Copy link

sonarqubecloud bot commented Mar 7, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants