org.springframework.boot:spring-boot-autoconfigure

Licenses: Apache-2.0

Direct Vulnerabilities

Known vulnerabilities in the org.springframework.boot:spring-boot-autoconfigure package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Insecure Temporary File

[,3.5.15)[4.0.0-M1,4.0.7)[4.1.0-M1,4.1.0)
  • L
Improper Validation of Certificate with Host Mismatch

[3.4.0,3.5.15)[4.0.0-M1,4.0.7)
  • C
Improper Validation of Certificate with Host Mismatch

[3.2.0,3.5.14)[4.0.0-M1,4.0.6)
  • C
Improper Validation of Certificate with Host Mismatch

[,3.5.14)[4.0.0-M1,4.0.6)
  • H
Denial of Service (DoS)

[,2.5.15)[2.6.0,2.6.15)[2.7.0,2.7.12)[3.0.0,3.0.7)

Package versions

290 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
4.1.010 Jun, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
4.1.0-RC123 Apr, 2026
  • 0
    C
  • 0
    H
  • 1
    M
  • 0
    L
4.1.0-M426 Mar, 2026
  • 0
    C
  • 0
    H
  • 1
    M
  • 0
    L
4.1.0-M320 Mar, 2026
  • 0
    C
  • 0
    H
  • 1
    M
  • 0
    L
4.1.0-M219 Feb, 2026
  • 0
    C
  • 0
    H
  • 1
    M
  • 0
    L
4.1.0-M122 Jan, 2026
  • 0
    C
  • 0
    H
  • 1
    M
  • 0
    L
4.0.710 Jun, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
4.0.623 Apr, 2026
  • 0
    C
  • 0
    H
  • 1
    M
  • 1
    L
4.0.526 Mar, 2026
  • 2
    C
  • 0
    H
  • 1
    M
  • 1
    L
4.0.419 Mar, 2026
  • 2
    C
  • 0
    H
  • 1
    M
  • 1
    L