Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Ingress NGINX
github.com/gomarkdown/markdown; reaches Ingress NGINX Controller via the bundled gomarkdown dependency
Denial of Service
<v0.0.0-20240729232818-a2a9c4f76ef5 (and Ingress NGINX builds that ship an earlier gomarkdown)
Apr 29, 2026
High
Ingress NGINX
github.com/gomarkdown/markdown; reaches Ingress NGINX Controller via the bundled gomarkdown dependency
Denial of Service
<v0.0.0-20260411013819-759bbc3e3207 (and Ingress NGINX builds that ship an earlier gomarkdown)
Apr 29, 2026
Medium
Ingress NGINX
Go (golang) standard library, os.Root API; reaches Ingress NGINX Controller via the Go toolchain it is built with
Improper Link Resolution Before File Access ('Link Following')
Go <1.25.9 and 1.26.0 through 1.26.1 (and Ingress NGINX builds compiled with them)
Apr 29, 2026
High
Ingress NGINX
Helm (Kubernetes package manager), helm.sh/helm/v4; reaches Ingress NGINX Controller via the bundled Helm dependency
Improper Verification of Cryptographic Signature
Helm 4.0.0 through 4.1.3 (and Ingress NGINX builds that ship them)
Apr 29, 2026
High
Ingress NGINX
Helm (Kubernetes package manager), helm.sh/helm/v4; reaches Ingress NGINX Controller via the bundled Helm dependency
Path Traversal
Helm 4.0.0 through 4.1.3 (and Ingress NGINX builds that ship them)
Apr 29, 2026
Medium
Spring
Spring Boot
Incorrectly Configured Access Control
>=1.3.0 <=2.7.32, >=3.0.0 <=3.3.18, >=3.4.0 <=3.4.15, >=3.5.0 <=3.5.13, >=4.0.0 <=4.0.5
Apr 25, 2026
Medium
Spring
Spring Boot
Path Traversal
>=1.0.2 <=2.7.32, >=3.3.0 <=3.3.18, >=3.4.0 <=3.4.15, >=3.5.0 <=3.5.13, >=4.0.0 <=4.0.5
Apr 25, 2026
Medium
Spring
Spring Boot
Information Exposure
>=1.0.0 <=3.5.13, >=4.0.0 <=4.0.5
Apr 25, 2026
High
Spring
Spring Boot
Incorrectly Configured Access Control
>=2.7.0 <=2.7.32, >=3.3.0 <=3.3.18, >=3.4.0 <=3.4.15, >=3.5.0 <=3.5.13, >=4.0.0 <=4.0.5
Apr 25, 2026
High
Spring
Spring Boot
Information Exposure
>=1.3.0 <=2.7.32, >=3.3.0 <=3.3.18, >=3.4.0 <=3.4.15, >=3.5.0 <=3.5.13, >=4.0.0 <=4.0.5
Apr 25, 2026
High
Angular
Angular
Server-Side Request Forgery
<=18.2.14, >=19.0.0-next.0 <19.2.21, >=20.0.0-next.0 <20.3.19, >=21.0.0-next.0 <21.2.9, >=22.0.0-next.0 <22.0.0-next.8
Apr 23, 2026
Critical
Spring
Spring Security
Authorization Bypass
1.3.x; 1.4.x; 1.5.x; 7.0.x
Apr 23, 2026
Medium
Spring
Spring Security
Weak Authentication
6.2.x; 6.3.x; 6.4.x; 6.5.x; 7.0.x
Apr 23, 2026
Low
Spring
Spring Security
Authorization Bypass
4.2.x; 5.5.x; 5.7.x; 5.8.x; 6.2.x; 6.3.x; 6.4.x; 6.5.x; 7.0.x
Apr 23, 2026
No results found
Please enter a valid Vulnerability ID number or Technology name.
