The latest version of spring-cloud-aws (3.4.0) presents vulnerabilities in some of the dependencies it makes use of:
- CVE-2025-58057 in
io.netty:netty-codec:4.1.123.Final , fixed in 4.1.125.Final
- CVE-2025-58056 in
io.netty:netty-codec-http:4.1.123.Final, fixed in 4.1.125.Final
- CVE-2025-55163 in
io.netty:netty-codec-http2:4.1.123.Final, fixed in 4.1.124.Final
- CVE-2025-48989 in
org.apache.tomcat.embed:tomcat-embed-core:10.1.43, fixed in 10.1.44
- CVE-2025-41242 in
org.springframework:spring-webmvc:6.2.9, fixed in 6.2.10
I'd like to request these be fixed in the next release.
The latest version of spring-cloud-aws (3.4.0) presents vulnerabilities in some of the dependencies it makes use of:
io.netty:netty-codec:4.1.123.Final, fixed in4.1.125.Finalio.netty:netty-codec-http:4.1.123.Final, fixed in4.1.125.Finalio.netty:netty-codec-http2:4.1.123.Final, fixed in4.1.124.Finalorg.apache.tomcat.embed:tomcat-embed-core:10.1.43, fixed in10.1.44org.springframework:spring-webmvc:6.2.9, fixed in6.2.10I'd like to request these be fixed in the next release.