CLEANSTART-2026-LS35751

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-LS35751.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-LS35751
Upstream
  • CVE-2026-47891
Published
2026-10-06T00:34:50Z
Modified
2026-10-06T01:00:14Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit
Details

Security vulnerability affects the rundeck package. A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.

References

Affected packages

CleanStart / rundeck

Package

Name
rundeck

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.1.0-r3

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-LS35751.json"