Spring
97 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-47849
HIGH 7.1
Spring Data Rest — Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 69…
2026-08-27
CVE-2026-47864
MEDIUM 6.4
Spring Integration — SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInput…
2026-08-27
CVE-2026-47875
MEDIUM 5.6
Spring Batch — Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable …
2026-08-27
CVE-2026-47877
HIGH 8.2
Spring Security — Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity…
2026-08-27
CVE-2026-47878
MEDIUM 5.6
Spring Batch — DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decode…
2026-08-27
CVE-2026-47879
HIGH 7.7
Spring Cloud Gateway — Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining th…
2026-08-27
CVE-2026-47880
MEDIUM 5.4
Spring Integration — A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can s…
2026-08-27
CVE-2026-47881
MEDIUM 5.9
Spring Batch — Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines —…
2026-08-27
CVE-2026-47883
MEDIUM 6.1
Spring Framework — UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. Th…
2026-08-27
CVE-2026-47884
CRITICAL 9.8
Spring Framework — Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" …
2026-08-27
CVE-2026-47885
HIGH 7.5
Spring Framework — The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize i…
2026-08-27
CVE-2026-47886
HIGH 7.5
Spring Framework — Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a …
2026-08-27
CVE-2026-47887
MEDIUM 6.1
Spring Framework — A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not …
2026-08-27
CVE-2026-47888
HIGH 7.5
Spring Framework — A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame.
Spring Framework 7.0.0 -…
2026-08-27
CVE-2026-47889
HIGH 7.5
Spring Framework — A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sa…
2026-08-27
CVE-2026-47890
CRITICAL 9.8
Spring Framework — Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) wi…
2026-08-27
CVE-2026-47891
CRITICAL 9.8
Spring Framework — A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enfo…
2026-08-27
CVE-2026-47892
N/A
Spring Framework — A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a he…
2026-08-27
CVE-2026-47893
N/A
Spring Framework — A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user informat…
2026-08-27
CVE-2026-47894
MEDIUM 4.9
Spring Cloud Config — Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the…
2026-08-27
CVE-2026-59270
CRITICAL 9.4
Spring Security — Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrat…
2026-08-27
CVE-2026-59271
MEDIUM 5.3
Spring Amqp — When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in …
2026-08-27
CVE-2026-59272
MEDIUM 6.8
Spring Amqp — Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default,…
2026-08-27
CVE-2026-59274
MEDIUM 6.5
Spring Integration — The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequen…
2026-08-27
CVE-2026-59275
MEDIUM 6.6
Spring Amqp — A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener t…
2026-08-27
CVE-2026-59276
MEDIUM 5.9
Spring Security — Several components in Spring Security compare security-sensitive values using standard string equality (String…
2026-08-27
CVE-2026-59277
LOW 3.7
Spring Security — Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constr…
2026-08-27
CVE-2026-59278
MEDIUM 6.5
Spring For Apache Kafka — JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. Wh…
2026-08-27
CVE-2026-59280
MEDIUM 4.3
Spring Framework — Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when…
2026-08-27
CVE-2026-59281
N/A
Spring Framework — Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and …
2026-08-27
CVE-2026-59282
N/A
Spring Framework — Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property pa…
2026-08-27
CVE-2026-59283
N/A
Spring Framework — Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be …
2026-08-27
CVE-2026-59284
MEDIUM 6.6
Spring Cloud Commons — There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled.
Spring C…
2026-08-27
CVE-2026-59285
N/A
Spring For Graphql — Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL que…
2026-08-27
CVE-2026-59286
N/A
Spring For Graphql — The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subres…
2026-08-27
CVE-2026-59287
N/A
Spring For Graphql — Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive e…
2026-08-27
CVE-2026-59288
N/A
Spring For Graphql — The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. …
2026-08-27
CVE-2026-59289
N/A
Spring For Graphql — Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the …
2026-08-27
CVE-2026-59291
LOW 2
Spring Cloud Function — Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.
Spring Cloud Function 5.0.0 - 5…
2026-08-27
CVE-2026-59292
LOW 3.2
Spring Integration — PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${jav…
2026-08-27
CVE-2026-59293
MEDIUM 6.6
Spring Integration — Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, whi…
2026-08-27
CVE-2026-59294
MEDIUM 5.9
Spring Ai — ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, withou…
2026-08-27
CVE-2026-59297
LOW 3.1
Spring Cloud Function — Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme.
Spring Cl…
2026-08-27
CVE-2026-59298
LOW 3.1
Spring Cloud Function — Potential for improper filtering of HTTP headers in Spring Cloud Function.
Spring Cloud Function 5.0.0 - 5.0.3…
2026-08-27
CVE-2026-59299
LOW 3.1
Spring Cloud Function — Composition lookup can potentially poison base function in Spring Cloud Function.
Spring Cloud Function 5.0.0 …
2026-08-27
CVE-2026-59300
LOW 3.1
Spring Cloud Function — Potential for logging sensitive data in Spring Cloud Function AWS.
Spring Cloud Function 5.0.0 - 5.0.3
Spring …
2026-08-27
CVE-2026-59301
LOW 3.1
Spring Cloud Function — Potential for logging sensitive data in Spring Cloud Function Azure.
Spring Cloud Function 5.0.0 - 5.0.3
Sprin…
2026-08-27
CVE-2026-59302
LOW 3.1
Spring Cloud Stream — Potential for logging sensitive data in Spring Cloud Stream.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring Cloud St…
2026-08-27
CVE-2026-59303
LOW 3.1
Spring Cloud Stream — Dynamic destination cache size is not properly bound in Spring Cloud Stream.
Spring Cloud Stream 5.0.0 - 5.0.2…
2026-08-27
CVE-2026-59304
LOW 3.1
Spring Cloud Stream — Improper caching of the original content type in Spring Cloud Stream Avro.
Spring Cloud Stream 5.0.0 - 5.0.2
S…
2026-08-27
CVE-2026-59305
LOW 3.1
Spring Cloud Stream — Partition interceptor may be improperly added while sending message.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring …
2026-08-27
CVE-2026-59306
LOW 3.1
Spring Cloud Stream — Potential for deserialization of untrusted types in Spring Cloud Stream.
Spring Cloud Stream 5.0.0 - 5.0.2
Spr…
2026-08-27
CVE-2026-59307
HIGH 8
Spring Integration — An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protect…
2026-08-27
CVE-2026-59311
MEDIUM 6.8
Spring Integration — A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of t…
2026-08-27
CVE-2026-59313
N/A
Spring Framework — Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Serv…
2026-08-27
CVE-2026-59314
N/A
Spring Framework — Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP resp…
2026-08-27
CVE-2026-59315
MEDIUM 5.3
Spring Cloud Config — The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads.
Spring Clo…
2026-08-27
CVE-2026-59316
HIGH 8.2
Spring Authorization Server — Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding…
2026-08-27
CVE-2026-59317
MEDIUM 6.5
Spring For Apache Kafka — DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerR…
2026-08-27
CVE-2026-59319
MEDIUM 4.3
Spring Ai — RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadat…
2026-08-27
CVE-2026-59320
MEDIUM 6.5
Spring Amqp — When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose pro…
2026-08-27
CVE-2026-59321
MEDIUM 4.2
Spring Integration — A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines tha…
2026-08-27
CVE-2026-59322
MEDIUM 6.3
Spring Integration — The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructo…
2026-08-27
CVE-2026-59324
HIGH 8.2
Spring Integration — When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payl…
2026-08-27
CVE-2026-47834
MEDIUM 4.8
Spring Data Jpa — Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from…
2026-08-26
CVE-2026-47836
HIGH 7.2
Spring Cloud Config — The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SV…
2026-08-26
CVE-2026-47837
MEDIUM 6.8
Spring Cloud Config — Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook reques…
2026-08-26
CVE-2026-47841
HIGH 7.4
Spring Security — An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when usi…
2026-08-26
CVE-2026-47842
MEDIUM 6.5
Spring Security — Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and…
2026-08-26
CVE-2026-47843
LOW 3.7
Reactor Netty — In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may…
2026-08-26
CVE-2026-47844
MEDIUM 5.3
Reactor Netty — In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In …
2026-08-26
CVE-2026-47845
MEDIUM 5.3
Reactor Netty — In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy P…
2026-08-26
CVE-2026-47848
MEDIUM 6.1
Reactor Netty — In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSock…
2026-08-26
CVE-2026-47850
MEDIUM 4.3
Spring Data Rest — Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handlin…
2026-08-26
CVE-2026-47851
HIGH 7.5
Spring Ai — Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingesti…
2026-08-26
CVE-2026-47852
HIGH 7.5
Spring Ai — A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX m…
2026-08-26
CVE-2026-47856
MEDIUM 6.3
Spring Integration — Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization ta…
2026-08-26
CVE-2026-47857
MEDIUM 5.9
Reactor Core — In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulne…
2026-08-26
CVE-2026-47859
MEDIUM 5.4
Spring Integration — RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC …
2026-08-26
CVE-2026-47860
MEDIUM 6.5
Spring Amqp — An attacker who can publish to a queue consumed by an application that has enabled message decompression can c…
2026-08-26
CVE-2026-47861
MEDIUM 6.3
Spring Integration — An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapte…
2026-08-26
CVE-2026-47862
MEDIUM 5.4
Spring Integration — An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (t…
2026-08-26
CVE-2026-47863
MEDIUM 5.9
Reactor Core — In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulne…
2026-08-26
CVE-2026-47874
MEDIUM 5.3
Reactor Netty — The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the…
2026-08-26
CVE-2026-41707
HIGH 7.4
Spring Security — Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPP…
2026-08-25
CVE-2026-59295
MEDIUM 5.9
Micrometer — It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service …
2026-08-24
CVE-2026-59279
HIGH 7.5
Spring Ai — The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number …
2026-08-21
CVE-2026-59296
MEDIUM 5.9
Micrometer — Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) i…
2026-08-21
CVE-2026-59308
MEDIUM 4.2
Spring Ai — In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different sys…
2026-08-21
CVE-2026-59318
MEDIUM 6.5
Spring Ai — In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is…
2026-08-21
CVE-2026-59323
MEDIUM 5.3
Micrometer Tracing — An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to deni…
2026-08-21
CVE-2026-47858
HIGH 8
Spring Tools For Eclipse — Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running…
2026-07-30
CVE-2026-47873
HIGH 8
Spring Tools For Eclipse — The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's n…
2026-07-30
CVE-2026-47882
HIGH 8.3
Spring Tools For Eclipse — When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or …
2026-07-30
CVE-2026-59326
LOW 3.3
Spring Tools For Eclipse — The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY enviro…
2026-07-30
CVE-2026-59327
MEDIUM 4.4
Spring Tools For Eclipse — Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a pl…
2026-07-30
CVE-2026-59328
MEDIUM 4.2
Spring Tools For Eclipse — Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (…
2026-07-30