Database Management
Why SolarWinds Database Performance Analyzer (DPA) is not affected by multiple Spring vulnerabilities
This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by the following Spring vulnerabilities: CVE-2026-47892 CVE-2026-47891 CVE-2026-47890 CVE-2026-59313 CVE-2026-59270 CVE-2026-59283
First published date
Last published date
Overview
In 2026, the National Institute of Standards and Technology (NIST) published security bulletins about the following vulnerabilities:
Product section
Cause
CVE-2026-47892 is a vulnerability within a WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request.
CVE-2026-47891 is a vulnerability in a Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
CVE-2026-47890 is a vulnerability in Spring MVC and WebFlux applications being vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments.
CVE-2026-59313 is a vulnerability in Spring MVC applications using the functional web framework being vulnerable to stream corruption when using Server-Sent Events (SSE)
CVE-2026-59270 is a vulnerability in Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.
CVE-2026-59283 is a vulnerability in applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active.
Resolution
SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-47892, CVE-2026-47891, CVE-2026-47890, CVE-2026-59313, CVE-2026-59270, and CVE-2026-59283.
CVE-2026-47891 and CVE-2026-47892: DPA does not use the vulnerable component, spring-webflux, therefore is not affected by this vulnerability.
CVE-2026-47890: DPA does not use the vulnerable component, Server-Sent Events (SSE) with view fragment, therefore is not affected by this vulnerability.
CVE-2026-59313: DPA does not use the vulnerable component, Spring MVC's functional web framework RouterFunction and ServerResponse.sse(). The application is not affected by this vulnerability.
CVE-2026-59270: DPA does not use the vulnerable component, Embedded UnboundID LDAP server (UnboundIdContainer) of Spring security, therefore is not affected by this vulnerability.
CVE-2026-59283: DPA does not use the vulnerable component, Spring Expression Language (SpEL) using SimpleEvaluationContext, therefore is not affected by this vulnerability.
While the component’s presence is flagged by dependency scanning tools, our analysis shows there is no associated security risk.