Vulnerabilities in spring
247 resultsVexday analysis
Spring apresenta 1 CVE na base Vexday, sem ocorrências de ataque ativo documentado (KEV). A vulnerabilidade é relacionada a falha em autenticação (CWE-287) e não foi publicada nos últimos 90 dias, indicando risco estável e consolidado.
CVE-2026-59303LOWDynamic destination cache size is not properly bound in Spring Cloud StreamEPSS 0.2%CVE-2026-59302LOWPotential for logging sensitive data in Spring Cloud StreamEPSS 0.1%CVE-2026-47844MEDIUMReactor Netty HTTP Server Leaks Exception DetailsEPSS 0.1%CVE-2026-40995MEDIUMX.509 authentication bypasses Spring Security account checksEPSS 0.1%CVE-2026-41694LOWSAML Payloads Decrypted Without Valid SignatureEPSS 0.1%CVE-2026-41844MEDIUMSpring Framework Open Redirect in Spring MVC and WebFluxEPSS 0.1%CVE-2026-59292LOWWorld-readable metadata file in PropertiesPersistingMetadataStore (insecure temp-file permissions)EPSS 0.1%CVE-2026-47836HIGHSpring Cloud Config Server Susceptible To TOCTOU Attack When Using SVNEPSS 0.1%CVE-2026-47825HIGHSpring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situationsEPSS 0.1%CVE-2026-40970MEDIUMWhen configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting EPSS 0.1%CVE-2026-40973HIGHA local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.seEPSS 0.1%CVE-2026-47838MEDIUMUnauthorized User Impersonation when Using X.509 Client CertificatesEPSS 0.1%CVE-2026-41714MEDIUMIn Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManagerEPSS 0.1%CVE-2026-40996MEDIUMInbound WS-Security allows RSA PKCS#1 v1.5 key transport by defaultEPSS 0.1%CVE-2026-59321MEDIUMShared JSR-223 ScriptEngine evaluated concurrently without THREADING checkEPSS 0.1%CVE-2026-40992MEDIUMMail Auto-Configuration Does Not Enable SSL Hostname VerificationEPSS 0.1%CVE-2026-22751MEDIUMSpring Security JdbcOneTimeTokenService allows a one-time token to authenticate multiple sessionsEPSS 0.1%CVE-2026-41854MEDIUMSpring Framework Server-Side Request Forgery via UriComponentsBuilderEPSS 0.1%CVE-2024-38807MEDIUMCVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's LoaderEPSS 0.1%CVE-2026-22735LOWServer Sent Event stream corruptionEPSS 0.1%