← Scan another repo

github.com/alibaba/easyexcel

@ aae9c61ab603

Submitted 8/4/2026, 10:28:01 AM · Status: ok

Risk grade
B
22 / 100
Findings
15
0 critical3 high9 medium3 low0 info0 on CISA KEV0ATT&CK
Showing 15 of 15 findings

Findings

  • Spring Framework annotation detection mechanism may result in improper authorization
    grypeCVE-2025-41249EPSS 0.5%
  • org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
    The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application m…
    trivyCVE-2025-41249
  • org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
    The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application m…
    trivyCVE-2025-41249
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Java CI)
    checkov.github/workflows/ci.yml:13
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Mirror the Github organization repos to Gitee)
    checkov.github/workflows/sync2gitee.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Publish package to the Maven Central Repository)
    checkov.github/workflows/release.yml:13
  • Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing
    grypeCVE-2025-31672EPSS 1.3%
  • Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing
    Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in t…
    osv-scannerCVE-2025-31672
  • Spring Framework annotation detection mechanism may result in improper authorization
    The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application m…
    osv-scannerCVE-2025-41249
  • Spring Framework Denial of Service via AntPathMatcher
    Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(Stri…
    osv-scannerCVE-2026-41848
  • org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
    Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in t…
    trivyCVE-2025-31672
  • org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names
    Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in t…
    trivyCVE-2025-31672
  • Spring Framework Denial of Service via AntPathMatcher
    grypeCVE-2026-41848EPSS 0.3%
  • spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher
    Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(Stri…
    trivyCVE-2026-41848
  • spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcher
    Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(Stri…
    trivyCVE-2026-41848

This report is public.