Highlights
Information Disclosure: 1 prior fix. Scrutinize any change in this area.
.github/workflows/maven.yml: most-fixed (1 issue). Treat as high-risk during review.
0 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Information Disclosure: Inadequate isolation of tracing context can lead to ThreadLocal state leakage across distinct RSocket requests sharing execution threads, exposing sensitive transaction or tenant details.
Privilege Escalation: Over-privileged GitHub workflow tokens can allow compromised build runners or dependencies to write back to the repository or escalate privileges within the organization.
Denial of Service: Specially crafted calls when Spring TX instrumentation is enabled can trigger resource exhaustion or service disruption, as documented in CVE-2026-41708.