Skip to content

[Aikido] Fix 1 critical issue in spring-security-core, spring-security-config, spring-security-web and 47 other issues - #7

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-130201397-sh64
Open

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-130201397-sh64

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 1, 2026

Copy link
Copy Markdown

Thank you for submitting a pull request to the WebGoat!


Summary / Description

Upgrade dependencies to fix critical RCE and arbitrary code execution vulnerabilities in XStream, Tomcat, Spring Security, Thymeleaf, and Jackson.


Security Impact — CVE vulnerabilities fixed by this PR

✅ 48 CVEs resolved by this upgrade, including 15 critical 🚨 CVEs

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2021-21345
🚨 CRITICAL
[xstream] A deserialization vulnerability allows remote attackers with sufficient rights to execute arbitrary commands by manipulating input streams. This impacts users relying on the default blacklist security framework rather than implementing a whitelist.
CVE-2013-7285
🚨 CRITICAL
[xstream] API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
CVE-2021-21344
🚨 CRITICAL
[xstream] A remote code execution vulnerability allows attackers to execute arbitrary code by manipulating input streams, bypassing the default blacklist security framework. Users relying on default security settings must upgrade to mitigate this risk.
CVE-2021-21346
🚨 CRITICAL
[xstream] A remote code execution vulnerability allows attackers to execute arbitrary code by manipulating input streams, bypassing the default blacklist security framework. Users relying on default security settings must upgrade to mitigate this risk.
CVE-2021-21347
🚨 CRITICAL
[xstream] A remote code execution vulnerability allows attackers to execute arbitrary code by manipulating input streams, bypassing the default blacklist security framework. Users relying on default security settings must upgrade to mitigate this risk.
CVE-2021-21350
🚨 CRITICAL
[xstream] Deserialization vulnerability allowing remote code execution through malicious XML input when using default blacklist security settings instead of a whitelist configuration.
CVE-2021-21342
🚨 CRITICAL
[xstream] Deserialization vulnerability allowing attackers to manipulate XML input streams to inject malicious objects, potentially causing server-side request forgery (SSRF) attacks during unmarshalling operations. Default blacklist configurations are vulnerable; whitelist-based security frameworks are unaffected.
CVE-2021-21351
🚨 CRITICAL
[xstream] Deserialization vulnerability allowing remote code execution through malicious XML input when using default blacklist security settings instead of a whitelist configuration.
CVE-2021-39144
🚨 CRITICAL
[xstream] A deserialization vulnerability allows remote attackers with sufficient rights to execute arbitrary commands by manipulating input streams. Users not using XStream's security framework with a whitelist are at risk.
CVE-2020-26217
HIGH
[xstream] A remote code execution vulnerability allows attackers to execute arbitrary shell commands by manipulating input streams when using blocklists. Users relying on allowlists are unaffected.
CVE-2021-29505
HIGH
[xstream] A deserialization vulnerability allows remote attackers to execute arbitrary commands on the host by manipulating input streams when security restrictions are not properly configured. Users with whitelisted type restrictions are not affected.
CVE-2021-21349
HIGH
[xstream] A vulnerability allows remote attackers to access internal resources by manipulating input streams, bypassing the default blacklist security framework. This enables information disclosure of non-public data when using default security settings.
CVE-2021-39141
HIGH
[xstream] Remote attackers can execute arbitrary code by manipulating input streams through unsafe deserialization. This vulnerability allows RCE unless XStream's security framework is configured with a strict whitelist of allowed types.
CVE-2021-39146
HIGH
[xstream] Remote attackers can execute arbitrary code by manipulating input streams through unsafe deserialization. This vulnerability allows RCE unless XStream's security framework is configured with a strict whitelist of allowed types.
CVE-2021-39152
HIGH
[xstream] A deserialization vulnerability allows remote attackers to access internal resources by manipulating input streams on Java 14-8 runtimes. This information disclosure issue bypasses the default blacklist security framework.
CVE-2021-39139
HIGH
[xstream] Deserialization vulnerability allowing remote code execution through malicious XML input when using default settings without security framework restrictions.
CVE-2020-26258
HIGH
[xstream] A Server-Side Request Forgery (SSRF) vulnerability in XStream's unmarshalling process allows remote attackers to access internal resources by manipulating input streams when using the default blacklist security configuration.
CVE-2017-7957
HIGH
[xstream] through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
CVE-2021-21341
HIGH
[xstream] A vulnerability allows remote attackers to cause denial of service by manipulating input streams to consume 100% CPU resources. This affects systems using default blacklist security settings; whitelist-based configurations are unaffected.
CVE-2022-41966
HIGH
[xstream] A remote attacker can manipulate input streams to trigger recursive hash calculations in collections, causing stack overflow and denial of service. The vulnerability exploits hash code implementations in maps and collections to crash the application.
CVE-2016-3674
HIGH
[xstream] Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
CVE-2021-39145
HIGH
[xstream] Remote attackers can execute arbitrary code by manipulating input streams through unsafe deserialization. This vulnerability allows RCE unless XStream's security framework is configured with a strict whitelist of allowed types.
CVE-2021-39147
HIGH
[xstream] Remote attackers can execute arbitrary code by manipulating input streams through unsafe deserialization. This vulnerability allows RCE unless XStream's security framework is configured with a strict whitelist of allowed types.
CVE-2021-39148
HIGH
[xstream] Remote attackers can execute arbitrary code by manipulating input streams through unsafe deserialization. This vulnerability allows RCE unless XStream's security framework is configured with a strict whitelist of allowed types.
CVE-2021-39149
HIGH
[xstream] Remote attackers can execute arbitrary code by manipulating input streams through unsafe deserialization. This vulnerability allows RCE unless XStream's security framework is configured with a strict whitelist of allowed types.
CVE-2021-39150
HIGH
[xstream] A deserialization vulnerability allows remote attackers to access internal resources by manipulating input streams on Java 14-8 runtimes. This information disclosure issue bypasses the default blacklist security framework.
CVE-2021-39151
HIGH
[xstream] Remote attackers can execute arbitrary code by manipulating input streams through unsafe deserialization. This vulnerability allows RCE unless XStream's security framework is configured with a strict whitelist of allowed types.
CVE-2021-39153
HIGH
[xstream] A deserialization vulnerability allows remote attackers to execute arbitrary code by manipulating input streams when using Java 14-8 or with JavaFX installed, unless XStream's security whitelist is properly configured.
CVE-2021-39154
HIGH
[xstream] Remote attackers can execute arbitrary code by manipulating input streams through unsafe deserialization. This vulnerability allows RCE unless XStream's security framework is configured with a strict whitelist of allowed types.
CVE-2021-21343
HIGH
[xstream] Deserialization vulnerability allowing arbitrary object instantiation during unmarshalling, enabling attackers to manipulate input streams and delete files on the local system through malicious type information injection.
CVE-2021-21348
HIGH
[xstream] Denial of Service vulnerability allowing remote attackers to consume maximum CPU resources through a malicious serialized object, causing thread hang. Affects systems using default blacklist security configuration.
CVE-2020-26259
MEDIUM
[xstream] XStream is vulnerable to arbitrary file deletion on the local host during unmarshalling when using default blacklist security settings. A remote attacker can delete arbitrary files if the executing process has sufficient permissions.
CVE-2022-40151
MEDIUM
[xstream] Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
CVE-2021-39140
MEDIUM
[xstream] A vulnerability allows remote attackers to cause denial of service by manipulating input streams to consume 100% CPU resources. This affects systems not using XStream's security framework with a whitelist of minimal required types.
CVE-2021-43859
LOW
[xstream] Deserialization vulnerability allowing remote attackers to cause denial of service by consuming 100% CPU through malicious input stream manipulation. Fixed by implementing time-based threshold monitoring for collection operations.
CVE-2026-41293
🚨 CRITICAL
[tomcat-embed-core] Improper input validation vulnerability allows attackers to bypass security controls or trigger unexpected behavior. Potential impacts include remote code execution, denial of service, or information disclosure depending on exploitation context.
CVE-2026-43512
🚨 CRITICAL
[tomcat-embed-core] Digest authentication bypass vulnerability allowing attackers to bypass authentication mechanisms and gain unauthorized access to protected resources.
CVE-2026-43515
🚨 CRITICAL
[tomcat-embed-core] Improper authorization in method constraints allows attackers to bypass HTTP method restrictions on specific file extensions, potentially enabling unauthorized access to protected resources.
CVE-2026-24880
HIGH
[tomcat-embed-core] HTTP request smuggling vulnerability via invalid chunk extensions allows attackers to bypass security controls and potentially execute arbitrary code or manipulate request handling.
CVE-2026-25854
MEDIUM
[tomcat-embed-core] Open redirect vulnerability in LoadBalancerDrainingValve allows attackers to redirect users to untrusted sites. This could enable phishing attacks or malicious redirects to compromise user security.
CVE-2025-61795
MEDIUM
[tomcat-embed-core] Temporary files from multipart uploads aren't cleaned up immediately during errors, allowing disk space to fill faster than garbage collection clears it, causing denial of service.
CVE-2026-22732
🚨 CRITICAL
[spring-security-core] HTTP response security headers may not be written to responses in servlet applications using lazy header writing, potentially allowing security headers to be bypassed and exposing applications to attacks that these headers would normally prevent.
CVE-2026-40477
🚨 CRITICAL
[thymeleaf-spring5] Server-Side Template Injection (SSTI) vulnerability allowing attackers to bypass expression restrictions and access sensitive objects through unvalidated user input. An unauthenticated remote attacker can execute arbitrary code on the server.
CVE-2026-41901
🚨 CRITICAL
[thymeleaf-spring5] Server-Side Template Injection (SSTI) vulnerability in sandboxed expression contexts allows attackers to execute arbitrary code when unsanitized user input is processed in restricted template contexts.
CVE-2026-40478
HIGH
[thymeleaf-spring5] Server-Side Template Injection (SSTI) vulnerability allowing attackers to bypass expression execution protections and execute unauthorized code through unvalidated user input. Remote code execution is possible when user input is passed directly to the template engine.
GHSA-r7wm-3cxj-wff9
HIGH
[jackson-core] Incomplete fix for number length validation in async parser allows attackers to bypass constraints by streaming JSON without terminators, causing unbounded memory accumulation up to 20 MiB per connection (~20,000x amplification of the configured limit). This enables denial-of-service through memory exhaustion in reactive frameworks.
CVE-2026-54512
HIGH
[jackson-databind] Polymorphic type validator bypass allows attackers to deserialize denied classes by hiding them as generic type parameters within allowed container types. This enables remote code execution through instantiation and property population of malicious gadget classes.
CVE-2026-54513
HIGH
[jackson-databind] BasicPolymorphicTypeValidator's allowIfSubTypeIsArray() method fails to validate array component types against the allowlist, allowing deserialization of non-allowlisted types as array elements. This bypasses type validation and enables remote code execution through malicious object instantiation.

Breaking Changes & Upgrade Impact

⚠️ Breaking changes analysis not available for: com.thoughtworks.xstream:xstream, com.fasterxml.jackson.core:jackson-databind

✅ No breaking changes for: org.apache.tomcat.embed:tomcat-embed-core, org.apache.tomcat:tomcat-coyote, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-util, org.apache.tomcat.embed:tomcat-embed-websocket, org.springframework.security:spring-security-core, org.springframework.security:spring-security-config, org.springframework.security:spring-security-web, org.thymeleaf:thymeleaf-spring5, org.thymeleaf:thymeleaf-spring6, org.thymeleaf:thymeleaf, com.fasterxml.jackson.core:jackson-core


Fix Details / Technical Implementation

🤖 Remediation details

Fix multiple critical/high/medium security vulnerabilities in Jackson, XStream, Tomcat, Spring Security, and Thymeleaf dependencies

Short summary

This PR remediates security vulnerabilities affecting five vulnerable package families declared or transitively resolved in the root pom.xml: com.thoughtworks.xstream:xstream, com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-core, Apache Tomcat (tomcat-embed-core, tomcat-embed-websocket, tomcat-coyote, tomcat-catalina, tomcat-util), org.springframework.security (spring-security-core, spring-security-config, spring-security-web), and org.thymeleaf (thymeleaf, thymeleaf-spring5, thymeleaf-spring6). Three edits were made to the root pom.xml: the spring-boot-starter-parent version was bumped, the xstream.version property was updated, and a jackson-bom.version property override was added.

com.thoughtworks.xstream:xstream

Declared directly in <dependencyManagement> via the ${xstream.version} property and consumed as a direct dependency. The xstream.version property was updated from 1.4.5 to 1.4.20 in <properties>, which is the minimum version that addresses the full range of XStream CVEs listed in this task (the highest patched floor across all advisories is 1.4.20, required by CVE-2022-41966 and CVE-2022-40151).

org.apache.tomcat.embed:tomcat-embed-core / org.apache.tomcat.embed:tomcat-embed-websocket / org.apache.tomcat:tomcat-coyote / org.apache.tomcat:tomcat-catalina / org.apache.tomcat:tomcat-util

All Tomcat artifacts are resolved transitively through spring-boot-starter-parent, which manages them via ${tomcat.version}. Bumping the parent from 3.5.6 to 3.5.16 advances tomcat.version from 10.1.46 to 10.1.55, satisfying the patched floor required by the Tomcat CVEs in this task (highest floor: 10.1.55).

org.springframework.security:spring-security-core / org.springframework.security:spring-security-config / org.springframework.security:spring-security-web

All Spring Security artifacts are resolved transitively through spring-boot-starter-parent via ${spring-security.version}. The parent bump from 3.5.6 to 3.5.16 advances spring-security.version from 6.5.5 to 6.5.11, satisfying the >= 6.5.9 patched floor required by CVE-2026-22732.

org.thymeleaf:thymeleaf / org.thymeleaf:thymeleaf-spring5 / org.thymeleaf:thymeleaf-spring6

Thymeleaf is resolved transitively through spring-boot-starter-parent via ${thymeleaf.version}. The project previously declared a local <thymeleaf.version>3.1.2.RELEASE</thymeleaf.version> property that overrode the parent-managed version, holding it below the patched floor. The parent bump to 3.5.16 advances the managed thymeleaf.version to 3.1.5.RELEASE (satisfying the >= 3.1.5.RELEASE floor for CVE-2026-40477, CVE-2026-41901, and CVE-2026-40478), and the now-redundant local override property was removed so the parent's patched version takes effect.

com.fasterxml.jackson.core:jackson-databind / com.fasterxml.jackson.core:jackson-core

Both Jackson core artifacts are resolved transitively through spring-boot-starter-parent, which imports com.fasterxml.jackson:jackson-bom using the ${jackson-bom.version} property. The parent 3.5.16 manages jackson-bom.version=2.21.4, which is below the 2.21.5 patched floor required by CVE-2026-59889 and GHSA-mhm7-754m-9p8w. The next Spring Boot release managing >= 2.21.5 is 4.0.8, a prohibited major-version jump, so a targeted <jackson-bom.version>2.21.5</jackson-bom.version> property override was added to <properties> in the root pom.xml. This overrides the BOM import in the parent, causing all Jackson artifacts to resolve at 2.21.5.

Version changes

Package From To Why updated
org.springframework.boot:spring-boot-starter-parent 3.5.6 3.5.16 Parent bump to transitively fix Tomcat, Spring Security, and Thymeleaf CVEs
com.thoughtworks.xstream:xstream 1.4.5 1.4.20 Direct CVE fix via xstream.version property
org.apache.tomcat.embed:tomcat-embed-core 10.1.46 10.1.55 Transitive after parent bump (spring-boot-starter-parent 3.5.16)
org.apache.tomcat.embed:tomcat-embed-websocket 10.1.46 10.1.55 Transitive after parent bump (spring-boot-starter-parent 3.5.16)
org.apache.tomcat:tomcat-coyote 10.1.46 10.1.55 Transitive after parent bump (spring-boot-starter-parent 3.5.16)
org.apache.tomcat:tomcat-catalina 10.1.46 10.1.55 Transitive after parent bump (spring-boot-starter-parent 3.5.16)
org.apache.tomcat:tomcat-util 10.1.46 10.1.55 Transitive after parent bump (spring-boot-starter-parent 3.5.16)
org.springframework.security:spring-security-core 6.5.5 6.5.11 Transitive after parent bump (spring-boot-starter-parent 3.5.16)
org.springframework.security:spring-security-config 6.5.5 6.5.11 Transitive after parent bump (spring-boot-starter-parent 3.5.16)
org.springframework.security:spring-security-web 6.5.5 6.5.11 Transitive after parent bump (spring-boot-starter-parent 3.5.16)
org.thymeleaf:thymeleaf 3.1.2.RELEASE 3.1.5.RELEASE Transitive after parent bump + removal of blocking local override
org.thymeleaf:thymeleaf-spring6 3.1.2.RELEASE 3.1.5.RELEASE Transitive after parent bump + removal of blocking local override
com.fasterxml.jackson.core:jackson-databind 2.21.4 2.21.5 Direct CVE fix via jackson-bom.version property override (parent major bump prohibited)
com.fasterxml.jackson.core:jackson-core 2.21.4 2.21.5 Transitive via jackson-bom.version property override (same BOM as jackson-databind)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants