Skip to content

[Snyk] Fix for 3 vulnerabilities#3668

Merged
hmiguim merged 1 commit into
developmentfrom
snyk-fix-02a2aa2898db74172fc3b25ddc261d75
May 4, 2026
Merged

[Snyk] Fix for 3 vulnerabilities#3668
hmiguim merged 1 commit into
developmentfrom
snyk-fix-02a2aa2898db74172fc3b25ddc261d75

Conversation

@AntonioG70
Copy link
Copy Markdown
Collaborator

snyk-top-banner

Snyk has created this PR to fix 3 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • pom.xml

Vulnerabilities that will be fixed with an upgrade:

Issue Upgrade
high severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGPOSTGRESQL-16321668
No Known Exploit
high severity Incomplete Cleanup
SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615
org.springframework:spring-web:
6.2.17 -> 6.2.18
No Known Exploit
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618
org.springframework:spring-core:
6.2.17 -> 6.2.18
org.springframework:spring-test:
6.2.17 -> 6.2.18
org.springframework:spring-web:
6.2.17 -> 6.2.18
No Known Exploit

Vulnerabilities that could not be fixed

  • Upgrade:
    • Could not upgrade org.postgresql:postgresql@42.7.10 to org.postgresql:postgresql@42.7.11; Reason could not apply upgrade, dependency is managed externally ; Location: https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/3.5.12/spring-boot-dependencies-3.5.12.pom

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling

@dosubot dosubot Bot added size:XS This PR changes 0-9 lines, ignoring generated files. dependencies Pull requests that update a dependency file labels May 4, 2026
@hmiguim hmiguim merged commit f36d466 into development May 4, 2026
5 checks passed
@hmiguim hmiguim deleted the snyk-fix-02a2aa2898db74172fc3b25ddc261d75 branch May 4, 2026 11:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants