Skip to content

Where does the CPE for CVE-2026-47838 come from #8614

Description

@marcelstoer

The ODC report for CVE-2026-47838 reports that it got the following CPE from OSS Index

cpe:2.3:a:org.springframework.security:spring-security-web:6.5.11:*:*:*:*:*:*:*

Yet, neither the GUI at https://guide.sonatype.com/vulnerability/CVE-2026-47838 nor the OSS Index JSON report contain any CPE. I didn't find any other source that has a CPE for this CVE. Hence, where did ODC really get it from?

It wouldn't really bother me if the CPE were correct. However, CVE-2026-47838 was fixed with Spring Security 6.5.11 (CPE should state spring-security-web:6.5.**10**).

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    ossindexLabel for issues that relate to the OSSIndex APIquestion

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions