Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
Source: NVD ↗ · CISA KEV Catalog ↗