
opentaint
Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293

spring retry 1.3.x fix with niche toolkit for CVE-2026-41710

Sean's Surf & Skate Co. — Spring Boot storefront with a vulnerable SnakeYAML dep (CVE-2022-1471) for Seal Security demos

Seal Security example — vulnerable Maven app (SnakeYAML CVE-2022-1471) remediated to sealed versions; GitHub Actions + Jenkins integration

Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target

Sentinel demo: transitive snakeyaml CVE-2022-1471 via Spring Boot + exploitable code pattern

Fork spring-webmvc 5.3.39 to fix CVE-2024-38816, CVE-2024-38819

Spring Web 5.x with `org.springframework.remoting` package removed, to fix CVE-2016-1000027.

Mitigated version for CVE-2016-1000027 spring web.

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

Reproduction of CVE-2020-36518 in Spring Boot 2.5.10