Skip to content

fix(deps): bump Spring Boot 3.4.0 → 3.4.13 (tomcat CVE-2025-24813, CVSS 10.0) - #6

Open
hajoeichler wants to merge 1 commit into
mainfrom
fix/security-dependency-upgrades
Open

fix(deps): bump Spring Boot 3.4.0 → 3.4.13 (tomcat CVE-2025-24813, CVSS 10.0)#6
hajoeichler wants to merge 1 commit into
mainfrom
fix/security-dependency-upgrades

Conversation

@hajoeichler

@hajoeichler hajoeichler commented Feb 18, 2026

Copy link
Copy Markdown
Member

Security: Dependency upgrades

This PR resolves high-severity vulnerabilities identified by Orca Security.

Changes

  • spring-boot-starter-parent 3.4.03.4.13
  • Cascades tomcat-embed-core from 10.1.3310.1.35

CVEs resolved

CVE-2025-24813 (Tomcat RCE, CVSS 10.0)

References

  • Orca Security alerts: Dependency Vulnerabilities (High)

Review checklist

  • Version bumps are correct
  • CI passes
  • No breaking changes in upgraded APIs

⚠️ Please review before merging. Automated security fix.

🤖 Generated with Claude Code

pom.xml: spring-boot 3.4.0 → 3.4.13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant