Vulnerability critical CVE-2022-1471 associated to org.yaml_snakeyaml version 1.30. Fixed in version 1.31.
Version 2.7.6 of spring-boot still use version 1.30.
Comment From: bclozel
Duplicates #33457 Also see #32221 to better understand our upgrade policy and why we can’t upgrade in 2.7.x.