GHSA-8hfc-fq58-r658
HIGHCVE-2026-22731Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path.
- Affected
- >= 3.4.0, <= 3.4.13
- Fixed in
- not stated
- Weakness
- CWE-288
- Published
- 2026-03-20
- Source
- github