Commit 567f6b0
committed
fix(security): bump contentstack-utils to 1.5.1 to address Spring CVEs
Bumps contentstack-utils-java: 1.3.0 → 1.5.1
Pulls in fixed transitive Spring Framework dependencies resolving:
- CVE-2026-41840 (High) - DoS via Multipart in WebFlux
- CVE-2026-41851 (High) - DoS via Unbounded SpEL Cache
- CVE-2026-41839 (Medium) - Session Fixation in WebFlux
- CVE-2026-41853 (Medium) - HTTP Request Smuggling
- CVE-2026-41854 (Medium) - SSRF
- CVE-2026-41845 (Medium) - XSS via JavaScriptUtils
- CVE-2026-41848 (Medium) - ReDoS via AntPathMatcher1 parent d57aaa1 commit 567f6b0
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
| 39 | + | |
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
| |||
0 commit comments