Detects Spring Boot applications 3.4.0–3.4.14, 3.5.0–3.5.11, 4.0.0–4.0.3 where the Actuator EndpointRequest matcher for health group additional paths generates overly broad patterns. When a health group is exposed at an additional server path (e.g., /healthz), the matcher also matches subpaths (/healthz/admin), allowing unauthenticated access to protected application endpoints that share the path prefix.
Is your app exploitable through CVE-2026-22731?
Scan your domain free