Vulnerability assessment for libcurl and Spring Framework CVEs in LiveUpdate Administrator
search cancel

Vulnerability assessment for libcurl and Spring Framework CVEs in LiveUpdate Administrator

book

Article ID: 449474

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

This article provides a security assessment for Symantec LiveUpdate Administrator (LUA) regarding several high-profile vulnerabilities reported in 2026 affecting libcurl and the Spring Framework.

libcurl 8.11.0 < 8.21.0 HTTP/3 Early Data Information DisclosureCVE-2026-9545
Spring Framework 5.3.x < 5.3.49 / 6.1.x < 6.1.28 / 6.2.x < 6.2.18.1 / 7.0.x < 7.0.7.1 Multiple VulnerabilitiesCVE-2026-41841,CVE-2026-41848,CVE-2026-41850,CVE-2026-41845,CVE-2026-41855,CVE-2026-41840,CVE-2026-41844,CVE-2026-41843,CVE-2026-41839,CVE-2026-41842,CVE-2026-41846,CVE-2026-41851,CVE-2026-41853,CVE-2026-41852,CVE-2026-41838
Spring Framework 5.3.x < 5.3.49 Multiple VulnerabilitiesCVE-2026-41849,CVE-2026-41847
Libcurl 7.12.0 < 8.21.0 Cross-Proxy Digest Auth State LeakCVE-2026-8927

Environment

LUA 2.3.14

Resolution

LiveUpdate Administrator (LUA) is not impacted by these vulnerabilities as it does not use libcurl, Spring Expression Language (SpEL), WebFlux, routing, the reactive stack, scriptUtils, or user-controlled input for tags.
It is free from all the components that caused these vulnerabilities.

Vulnerability scanners may flag the version numbers of bundled third-party libraries (e.g., libcurl.dll or spring-core-####.jar). However, LUA is not exploitable because it does not utilize the affected modules or features.