github.com/alibaba/easyexcel
Submitted 8/4/2026, 10:28:01 AM · Status: ok
Risk grade
B
22 / 100
Findings
15
0 critical3 high9 medium3 low0 info0 on CISA KEV0ATT&CK
Showing 15 of 15 findings
Findings
- Spring Framework annotation detection mechanism may result in improper authorizationgrypeCVE-2025-41249EPSS 0.5%
- org.springframework/spring-core: Spring Framework Annotation Detection VulnerabilityThe Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application m…trivyCVE-2025-41249
- org.springframework/spring-core: Spring Framework Annotation Detection VulnerabilityThe Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application m…trivyCVE-2025-41249
- Ensure top-level permissions are not set to write-allEnsure top-level permissions are not set to write-all on on(Java CI)checkov.github/workflows/ci.yml:13
- Ensure top-level permissions are not set to write-allEnsure top-level permissions are not set to write-all on on(Mirror the Github organization repos to Gitee)checkov.github/workflows/sync2gitee.yml:0
- Ensure top-level permissions are not set to write-allEnsure top-level permissions are not set to write-all on on(Publish package to the Maven Central Repository)checkov.github/workflows/release.yml:13
- Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File ParsinggrypeCVE-2025-31672EPSS 1.3%
- Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File ParsingImproper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in t…osv-scannerCVE-2025-31672
- Spring Framework annotation detection mechanism may result in improper authorizationThe Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application m…osv-scannerCVE-2025-41249
- Spring Framework Denial of Service via AntPathMatcherApplications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(Stri…osv-scannerCVE-2026-41848
- org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry namesImproper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in t…trivyCVE-2025-31672
- org.apache.poi/poi-ooxml: Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry namesImproper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, docx and pptx. These file formats are basically zip files and it is possible for malicious users to add zip entries with duplicate names (including the path) in t…trivyCVE-2025-31672
- Spring Framework Denial of Service via AntPathMatchergrypeCVE-2026-41848EPSS 0.3%
- spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcherApplications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(Stri…trivyCVE-2026-41848
- spring-framework: Spring Framework: Regular Expression Denial of Service in AntPathMatcherApplications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(Stri…trivyCVE-2026-41848
This report is public.