5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.springframework.boot:spring-boot is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.0
CVE-2026-40973
Spring Boot accepts predictable temp directory without ownership verification
CRITICAL 9.1
CVE-2026-40976
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
HIGH 7.3
CVE-2025-22235
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
HIGH 7.8
CVE-2022-27772
Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-boot
MEDIUM 5.9
CVE-2018-1196
Moderate severity vulnerability that affects org.springframework.boot:spring-boot
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes