
opentaint
Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293

spring retry 1.3.x fix with niche toolkit for CVE-2026-41710

Sean's Surf & Skate Co. — Spring Boot storefront with a vulnerable SnakeYAML dep (CVE-2022-1471) for Seal Security demos

Spring Framework CVE-2022-22965 本地影响条件验证、版本升级修复与复测项目

CVE-2026-21876 PoC: WAF charset bypass (Flask, ASP.NET and Spring Boot stands)


Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target

DOM-based Cross-Site Scripting (XSS) Vulnerability in novel V3.5.0 (CWE-79)




Fork spring-webmvc 5.3.39 to fix CVE-2024-38816, CVE-2024-38819

This demo application partially covers the vulnerability CVE-2024-38828

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

Demonstration of CVE-2023-24034 authorization bypass in Spring Security