Multiple security vulnerabilities affect the spring-boot package. Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. See references for individual vulnerability details.