vulnerability in rootio-pillow (ROOT-APP-PYPI-CVE-2026-42308). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.1.0+root.io.4` or later.
vulnerability in io.root.org.springframework:spring-web (ROOT-APP-MAVEN-CVE-2025-41234). Confidential information can be exposed externally. Mitigation: upgrade to `6.0.11-root.io.4, 6.2.5-root.io.2, 6.0.11-root.io.6, 6.1.20-root.io.5, 6.2.5-root.io.3, 6.2.5-root.io.4, 6.2.2-root.io.2, 6.1.1-root.io.2` or later.
vulnerability in io.root.org.springframework:spring-webmvc (ROOT-APP-MAVEN-CVE-2026-22745). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.6-root.io.1, 6.2.5-root.io.4, 6.2.2-root.io.2, 6.2.17-root.io.2, 6.1.1-root.io.2` or later.
vulnerability in io.root.org.springframework:spring-webmvc (ROOT-APP-MAVEN-CVE-2025-41242). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.2.5-root.io.3, 6.2.5-root.io.4, 6.2.2-root.io.2, 6.1.1-root.io.2` or later.
vulnerability in io.root.org.springframework:spring-webmvc (ROOT-APP-MAVEN-CVE-2026-22737). Confidential information can be exposed externally. Mitigation: upgrade to `6.2.5-root.io.3, 6.2.5-root.io.4, 6.2.2-root.io.2, 6.1.1-root.io.2, 7.0.6-root.io.1, 6.2.17-root.io.2` or later.
vulnerability in io.root.org.springframework:spring-webmvc (ROOT-APP-MAVEN-CVE-2026-22741). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.6-root.io.1, 6.2.5-root.io.4, 6.2.2-root.io.2, 6.2.17-root.io.2, 6.1.1-root.io.2` or later.
vulnerability in @rootio/http-proxy (ROOT-APP-NPM-GHSA-6x33-pw7p-hmpq). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.11.1-root.io.1` or later.
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41168). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.9` or later.