Vulnerabilities in spring
247 resultsVexday analysis
Spring apresenta 1 CVE na base Vexday, sem ocorrências de ataque ativo documentado (KEV). A vulnerabilidade é relacionada a falha em autenticação (CWE-287) e não foi publicada nos últimos 90 dias, indicando risco estável e consolidado.
CVE-2026-59328MEDIUMCross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency TooltipsEPSS 0.2%CVE-2026-40968MEDIUMSpring gRPC SecurityContext leaks across requests on authorization failureEPSS 0.2%CVE-2026-41838MEDIUMSpring Framework Predictable Session ID in WebSocket ModuleEPSS 0.2%CVE-2026-41004MEDIUMWhen enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs.
Spring Cloud Config 3.EPSS 0.2%CVE-2026-47843LOWReactor Netty may incorrectly route traffic due to DNS resolver reuseEPSS 0.2%CVE-2026-41847MEDIUMSpring Framework Security Filter Bypass in WebFlux Kotlin Router DSLEPSS 0.2%CVE-2026-59301LOWPotential for logging sensitive data in Spring Cloud Function AzureEPSS 0.2%CVE-2026-47877HIGHSpring Security Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS)EPSS 0.2%CVE-2026-59308MEDIUMSemantic Cache Cross-Tenant Isolation Bypass via SHA-256 TruncationEPSS 0.2%CVE-2026-59272MEDIUMLog4j2 AmqpAppender disables TLS hostname verification by defaultEPSS 0.2%CVE-2026-41845HIGHSpring Framework Cross-site Scripting via JavaScriptUtilsEPSS 0.2%CVE-2026-59298LOWPotential for improper filtering of HTTP headers in Spring Cloud FunctionEPSS 0.2%CVE-2026-59278MEDIUMIn Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types in header mapper default trusted packagesEPSS 0.2%CVE-2026-47848MEDIUMReactor Netty WebSocket Client Leaks Credentials On RedirectEPSS 0.2%CVE-2026-40971MEDIUMWhen configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to thEPSS 0.2%CVE-2026-41846MEDIUMSpring Framework Cross-site Scripting via JSP Form TagsEPSS 0.2%CVE-2026-59305LOWPartition interceptor may be improperly added while sending messageEPSS 0.2%CVE-2026-59300LOWPotential for logging sensitive data in Spring Cloud Function AWSEPSS 0.2%CVE-2026-59299LOWComposition lookup can potentially poison base function in Spring Cloud FunctionEPSS 0.2%CVE-2026-59304LOWImproper caching of the original content type in Spring Cloud Stream AvroEPSS 0.2%