VYPR

Spring for Apache Pulsar

by Spring Projects

CVEs (1)

  • CVE-2026-41732HigJun 10, 2026
    risk 0.53cvss 8.1epss 0.00

    JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rather than applying a…