Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.
{
"cwe_ids": [
"CWE-1188"
],
"github_reviewed": true,
"github_reviewed_at": "2025-07-07T12:45:39Z",
"nvd_published_at": "2025-07-04T21:15:23Z",
"severity": "MODERATE"
}