Vulnerabilities in spring
247 resultsVexday analysis
Spring apresenta 1 CVE na base Vexday, sem ocorrências de ataque ativo documentado (KEV). A vulnerabilidade é relacionada a falha em autenticação (CWE-287) e não foi publicada nos últimos 90 dias, indicando risco estável e consolidado.
CVE-2026-40977MEDIUMWhen an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corruEPSS 0.1%CVE-2026-40979MEDIUMIn Spring AI, having access to a shared environment can expose the ONNX model used by the application.
Affected versions:
Spring AI: 1.0.0 EPSS 0.1%CVE-2026-59297LOWSpring Cloud Function can incorrectly determine if URI is secureEPSS 0.1%CVE-2026-59326LOWHTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language ServerEPSS 0.1%CVE-2026-47842MEDIUMDeterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows Ciphertext CorrelationEPSS 0.1%CVE-2026-41001MEDIUMPredictable Temp Directory in Artemis Auto-configurationEPSS 0.1%CVE-2026-59327MEDIUMCleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch ConfigurationsEPSS 0.1%