{"api_version":"v1","generated_at":"2026-10-06T03:30:00+00:00","product":{"cve_count":15,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-spring-spring-boot-13df0e931da3","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/spring-boot","name":"Spring Boot","next_cursor":null,"observations":[{"affected":"4.0.0 < 4.0.6.1; 3.5.0 < 3.5.14.1; 3.4.0 < 3.4.17; 3.3.0 < 3.3.20; 2.7.0 < 2.7.34","affected_versions_present":true,"cve_id":"CVE-2026-41001","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41001","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-23T19:54:20.854Z","patch_url":"","primary_source":"","published":"2026-06-11T05:04:28.663Z"},{"affected":"4.0.0 < 4.0.6.1; 3.5.0 < 3.5.14.1; 3.4.0 < 3.4.17","affected_versions_present":true,"cve_id":"CVE-2026-40992","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40992","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-23T19:46:36.493Z","patch_url":"","primary_source":"","published":"2026-06-11T05:03:53.539Z"},{"affected":"4.0.0 < 4.0.6; 3.5.0 < 3.5.14; 3.4.0 < 3.4.16; 3.3.0 < 3.3.19; 2.7.0 < 2.7.33","affected_versions_present":true,"cve_id":"CVE-2026-40977","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40977","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T14:34:36.220Z","patch_url":"","primary_source":"","published":"2026-04-27T23:36:06.654Z"},{"affected":"4.0.0 < 4.0.6","affected_versions_present":true,"cve_id":"CVE-2026-40976","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40976","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:00:17.230Z","patch_url":"","primary_source":"","published":"2026-04-27T23:34:51.422Z"},{"affected":"4.0.0 < 4.0.6; 3.5.0 < 3.5.14; 3.4.0 < 3.4.16; 3.3.0 < 3.3.19; 2.7.0 < 2.7.33","affected_versions_present":true,"cve_id":"CVE-2026-40975","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40975","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-07-15T01:00:19.147Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-40975","primary_source":"","published":"2026-04-27T23:32:58.596Z"},{"affected":"4.0.0 < 4.0.6; 3.5.0 < 3.5.14; 3.4.0 < 3.4.16; 3.3.0 < 3.3.19; 2.7.0 < 2.7.33","affected_versions_present":true,"cve_id":"CVE-2026-40974","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40974","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T12:41:52.250Z","patch_url":"","primary_source":"","published":"2026-04-27T23:31:40.629Z"},{"affected":"4.0.0 < 4.0.6; 3.5.0 < 3.5.14; 3.4.0 < 3.4.16; 3.3.0 < 3.3.19; 2.7.0 < 2.7.33","affected_versions_present":true,"cve_id":"CVE-2026-40973","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40973","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-29T03:55:43.148Z","patch_url":"","primary_source":"","published":"2026-04-27T23:29:51.946Z"},{"affected":"4.0.0 < 4.0.6; 3.5.0 < 3.5.14; 3.4.0 < 3.4.16; 3.3.0 < 3.3.19; 2.7.0 < 2.7.33","affected_versions_present":true,"cve_id":"CVE-2026-40972","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40972","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-29T03:55:44.263Z","patch_url":"","primary_source":"","published":"2026-04-27T23:15:19.194Z"},{"affected":"4.0.0 < 4.0.6; 3.5.0 < 3.5.14","affected_versions_present":true,"cve_id":"CVE-2026-40971","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40971","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T12:46:29.029Z","patch_url":"","primary_source":"","published":"2026-04-27T22:45:13.327Z"},{"affected":"4.0.0 < 4.0.6","affected_versions_present":true,"cve_id":"CVE-2026-40970","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40970","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-27T19:30:55.167Z","patch_url":"","primary_source":"","published":"2026-04-27T19:09:58.835Z"},{"affected":"4.0 < 4.0.3; 3.5 < 3.5.11; 3.4 < 3.4.15","affected_versions_present":true,"cve_id":"CVE-2026-22731","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22731","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-03-20T15:33:43.191Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-22731","primary_source":"","published":"2026-03-19T22:36:15.112Z"},{"affected":"2.7.x < 2.7.25; 3.1.x < 3.1.16; 3.2.x < 3.2.14; 3.3.x < 3.3.11; 3.4.x < 3.4.5","affected_versions_present":true,"cve_id":"CVE-2025-22235","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-22235","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-16T23:03:06.227Z","patch_url":"","primary_source":"","published":"2025-04-28T07:10:35.370Z"},{"affected":"2.7.x < 2.7.22; 3.0.x < 3.0.17; 3.1.x < 3.1.13; 3.2.x < 3.2.9; 3.3.x < 3.3.3","affected_versions_present":true,"cve_id":"CVE-2024-38807","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-38807","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-03-27T16:36:21.258Z","patch_url":"","primary_source":"","published":"2024-08-23T08:26:11.826Z"},{"affected":"2.7.0 < 2.7.18; 3.0.0 < 3.0.13; 3.1.0 < 3.1.6; older unsupported versions","affected_versions_present":true,"cve_id":"CVE-2023-34055","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-34055","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-02-13T16:55:15.158Z","patch_url":"https://access.redhat.com/security/cve/CVE-2023-34055","primary_source":"","published":"2023-11-28T08:27:25.132Z"},{"affected":"2.0 < v2.0.9.RELEASE; 1.5 < v1.5.20.RELEASE; 2.1 < v2.1.4.RELEASE","affected_versions_present":true,"cve_id":"CVE-2019-3797","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-3797","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-16T17:33:03.727Z","patch_url":"","primary_source":"","published":"2019-05-06T15:21:37.081Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"Spring"}}
