Skip to content

[FP]: CVE-2026-47842 reported against fixed version 7.1.1 #8776

Description

@xcq1

Package URl

pkg:maven/org.springframework.security/spring-security-crypto@7.1.1

CPE

cpe:2.3:a:pivotal_software:spring_security:7.1.1

CVE

CVE-2026-47842

ODC Integration

{"label" => "Gradle Plugin"}

ODC Version

13.0.0

Description

I'm seeing CVE-2026-47842 which according to NIST, Sonatype, and Spring should only apply to <=7.1.0 and 7.1.1 being a recommended fix version.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions