Repository navigation
Conversation
github-actions
Bot
changed the base branch from
main
to
ranjiGT/advisory-improvement-10232
October 8, 2026 18:25
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Four enterprise-only versions are incorrectly used as public Maven fixed-version boundaries.
0 open findings
What changed in this PR
Improves GHSA-549f-4rpc-3rw9 with Spring Framework package, version, remediation, and source metadata.
Changes:
- Adds affected Maven ranges and fixed-version guidance.
- Adds upstream issue, commits, repository, and release references.
- Expands the summary and vulnerability details.
| File | Description |
|---|---|
advisories/unreviewed/2026/08/GHSA-549f-4rpc-3rw9/GHSA-549f-4rpc-3rw9.json |
Enriches the Spring Framework advisory metadata. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates
Comments
Reason for Change
This contribution improves the accuracy and completeness of
GHSA-549f-4rpc-3rw9 (CVE-2026-59281) by adding:
org.springframework:spring-web.Technical Details
The vulnerability originates in the
spring-webmodule, specifically:org.springframework.web.bind.EscapedErrorsThe no-argument
getFieldErrors()andgetFieldError()methods previouslyreturned field errors without consistently applying HTML escaping.
The upstream fix updates these methods to use the existing escaping
helpers and introduces regression tests covering HTML escaping of
rejected values and error messages.
Upstream Verification
Version Mapping
The affected version ranges follow the official Spring security advisory.
Spring Framework 7.0.9 is the documented open-source fixed release.
The fixes for older supported branches are designated
Enterprise Support Only by Spring.
The 5.2.x-and-earlier affected-product entry intentionally leaves the
patched Maven version unspecified because the exact enterprise artifact
version has not been independently verified.
Expected Improvement
These changes provide more complete package and version metadata
for vulnerability identification, dependency scanning, and
security advisory tracking.