← Browse

Spring

97 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-47849 HIGH 7.1 Spring Data Rest — Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 69… 2026-08-27 CVE-2026-47864 MEDIUM 6.4 Spring Integration — SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInput… 2026-08-27 CVE-2026-47875 MEDIUM 5.6 Spring Batch — Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable … 2026-08-27 CVE-2026-47877 HIGH 8.2 Spring Security — Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity… 2026-08-27 CVE-2026-47878 MEDIUM 5.6 Spring Batch — DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decode… 2026-08-27 CVE-2026-47879 HIGH 7.7 Spring Cloud Gateway — Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining th… 2026-08-27 CVE-2026-47880 MEDIUM 5.4 Spring Integration — A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can s… 2026-08-27 CVE-2026-47881 MEDIUM 5.9 Spring Batch — Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines —… 2026-08-27 CVE-2026-47883 MEDIUM 6.1 Spring Framework — UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. Th… 2026-08-27 CVE-2026-47884 CRITICAL 9.8 Spring Framework — Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" … 2026-08-27 CVE-2026-47885 HIGH 7.5 Spring Framework — The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize i… 2026-08-27 CVE-2026-47886 HIGH 7.5 Spring Framework — Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a … 2026-08-27 CVE-2026-47887 MEDIUM 6.1 Spring Framework — A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not … 2026-08-27 CVE-2026-47888 HIGH 7.5 Spring Framework — A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 -… 2026-08-27 CVE-2026-47889 HIGH 7.5 Spring Framework — A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sa… 2026-08-27 CVE-2026-47890 CRITICAL 9.8 Spring Framework — Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) wi… 2026-08-27 CVE-2026-47891 CRITICAL 9.8 Spring Framework — A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enfo… 2026-08-27 CVE-2026-47892 N/A Spring Framework — A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a he… 2026-08-27 CVE-2026-47893 N/A Spring Framework — A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user informat… 2026-08-27 CVE-2026-47894 MEDIUM 4.9 Spring Cloud Config — Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the… 2026-08-27 CVE-2026-59270 CRITICAL 9.4 Spring Security — Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrat… 2026-08-27 CVE-2026-59271 MEDIUM 5.3 Spring Amqp — When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in … 2026-08-27 CVE-2026-59272 MEDIUM 6.8 Spring Amqp — Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default,… 2026-08-27 CVE-2026-59274 MEDIUM 6.5 Spring Integration — The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequen… 2026-08-27 CVE-2026-59275 MEDIUM 6.6 Spring Amqp — A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener t… 2026-08-27 CVE-2026-59276 MEDIUM 5.9 Spring Security — Several components in Spring Security compare security-sensitive values using standard string equality (String… 2026-08-27 CVE-2026-59277 LOW 3.7 Spring Security — Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constr… 2026-08-27 CVE-2026-59278 MEDIUM 6.5 Spring For Apache Kafka — JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. Wh… 2026-08-27 CVE-2026-59280 MEDIUM 4.3 Spring Framework — Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when… 2026-08-27 CVE-2026-59281 N/A Spring Framework — Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and … 2026-08-27 CVE-2026-59282 N/A Spring Framework — Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property pa… 2026-08-27 CVE-2026-59283 N/A Spring Framework — Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be … 2026-08-27 CVE-2026-59284 MEDIUM 6.6 Spring Cloud Commons — There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring C… 2026-08-27 CVE-2026-59285 N/A Spring For Graphql — Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL que… 2026-08-27 CVE-2026-59286 N/A Spring For Graphql — The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subres… 2026-08-27 CVE-2026-59287 N/A Spring For Graphql — Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive e… 2026-08-27 CVE-2026-59288 N/A Spring For Graphql — The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. … 2026-08-27 CVE-2026-59289 N/A Spring For Graphql — Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the … 2026-08-27 CVE-2026-59291 LOW 2 Spring Cloud Function — Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5… 2026-08-27 CVE-2026-59292 LOW 3.2 Spring Integration — PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${jav… 2026-08-27 CVE-2026-59293 MEDIUM 6.6 Spring Integration — Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, whi… 2026-08-27 CVE-2026-59294 MEDIUM 5.9 Spring Ai — ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, withou… 2026-08-27 CVE-2026-59297 LOW 3.1 Spring Cloud Function — Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cl… 2026-08-27 CVE-2026-59298 LOW 3.1 Spring Cloud Function — Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3… 2026-08-27 CVE-2026-59299 LOW 3.1 Spring Cloud Function — Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 … 2026-08-27 CVE-2026-59300 LOW 3.1 Spring Cloud Function — Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring … 2026-08-27 CVE-2026-59301 LOW 3.1 Spring Cloud Function — Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Sprin… 2026-08-27 CVE-2026-59302 LOW 3.1 Spring Cloud Stream — Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud St… 2026-08-27 CVE-2026-59303 LOW 3.1 Spring Cloud Stream — Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2… 2026-08-27 CVE-2026-59304 LOW 3.1 Spring Cloud Stream — Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 S… 2026-08-27 CVE-2026-59305 LOW 3.1 Spring Cloud Stream — Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring … 2026-08-27 CVE-2026-59306 LOW 3.1 Spring Cloud Stream — Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spr… 2026-08-27 CVE-2026-59307 HIGH 8 Spring Integration — An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protect… 2026-08-27 CVE-2026-59311 MEDIUM 6.8 Spring Integration — A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of t… 2026-08-27 CVE-2026-59313 N/A Spring Framework — Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Serv… 2026-08-27 CVE-2026-59314 N/A Spring Framework — Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP resp… 2026-08-27 CVE-2026-59315 MEDIUM 5.3 Spring Cloud Config — The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Clo… 2026-08-27 CVE-2026-59316 HIGH 8.2 Spring Authorization Server — Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding… 2026-08-27 CVE-2026-59317 MEDIUM 6.5 Spring For Apache Kafka — DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerR… 2026-08-27 CVE-2026-59319 MEDIUM 4.3 Spring Ai — RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadat… 2026-08-27 CVE-2026-59320 MEDIUM 6.5 Spring Amqp — When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose pro… 2026-08-27 CVE-2026-59321 MEDIUM 4.2 Spring Integration — A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines tha… 2026-08-27 CVE-2026-59322 MEDIUM 6.3 Spring Integration — The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructo… 2026-08-27 CVE-2026-59324 HIGH 8.2 Spring Integration — When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payl… 2026-08-27 CVE-2026-47834 MEDIUM 4.8 Spring Data Jpa — Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from… 2026-08-26 CVE-2026-47836 HIGH 7.2 Spring Cloud Config — The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SV… 2026-08-26 CVE-2026-47837 MEDIUM 6.8 Spring Cloud Config — Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook reques… 2026-08-26 CVE-2026-47841 HIGH 7.4 Spring Security — An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when usi… 2026-08-26 CVE-2026-47842 MEDIUM 6.5 Spring Security — Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and… 2026-08-26 CVE-2026-47843 LOW 3.7 Reactor Netty — In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may… 2026-08-26 CVE-2026-47844 MEDIUM 5.3 Reactor Netty — In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In … 2026-08-26 CVE-2026-47845 MEDIUM 5.3 Reactor Netty — In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy P… 2026-08-26 CVE-2026-47848 MEDIUM 6.1 Reactor Netty — In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSock… 2026-08-26 CVE-2026-47850 MEDIUM 4.3 Spring Data Rest — Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handlin… 2026-08-26 CVE-2026-47851 HIGH 7.5 Spring Ai — Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingesti… 2026-08-26 CVE-2026-47852 HIGH 7.5 Spring Ai — A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX m… 2026-08-26 CVE-2026-47856 MEDIUM 6.3 Spring Integration — Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization ta… 2026-08-26 CVE-2026-47857 MEDIUM 5.9 Reactor Core — In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulne… 2026-08-26 CVE-2026-47859 MEDIUM 5.4 Spring Integration — RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC … 2026-08-26 CVE-2026-47860 MEDIUM 6.5 Spring Amqp — An attacker who can publish to a queue consumed by an application that has enabled message decompression can c… 2026-08-26 CVE-2026-47861 MEDIUM 6.3 Spring Integration — An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapte… 2026-08-26 CVE-2026-47862 MEDIUM 5.4 Spring Integration — An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (t… 2026-08-26 CVE-2026-47863 MEDIUM 5.9 Reactor Core — In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulne… 2026-08-26 CVE-2026-47874 MEDIUM 5.3 Reactor Netty — The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the… 2026-08-26 CVE-2026-41707 HIGH 7.4 Spring Security — Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPP… 2026-08-25 CVE-2026-59295 MEDIUM 5.9 Micrometer — It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service … 2026-08-24 CVE-2026-59279 HIGH 7.5 Spring Ai — The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number … 2026-08-21 CVE-2026-59296 MEDIUM 5.9 Micrometer — Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) i… 2026-08-21 CVE-2026-59308 MEDIUM 4.2 Spring Ai — In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different sys… 2026-08-21 CVE-2026-59318 MEDIUM 6.5 Spring Ai — In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is… 2026-08-21 CVE-2026-59323 MEDIUM 5.3 Micrometer Tracing — An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to deni… 2026-08-21 CVE-2026-47858 HIGH 8 Spring Tools For Eclipse — Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running… 2026-07-30 CVE-2026-47873 HIGH 8 Spring Tools For Eclipse — The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's n… 2026-07-30 CVE-2026-47882 HIGH 8.3 Spring Tools For Eclipse — When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or … 2026-07-30 CVE-2026-59326 LOW 3.3 Spring Tools For Eclipse — The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY enviro… 2026-07-30 CVE-2026-59327 MEDIUM 4.4 Spring Tools For Eclipse — Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a pl… 2026-07-30 CVE-2026-59328 MEDIUM 4.2 Spring Tools For Eclipse — Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (… 2026-07-30