Vulnerabilities in spring
247 resultsVexday analysis
Spring apresenta 1 CVE na base Vexday, sem ocorrências de ataque ativo documentado (KEV). A vulnerabilidade é relacionada a falha em autenticação (CWE-287) e não foi publicada nos últimos 90 dias, indicando risco estável e consolidado.
CVE-2026-41841MEDIUMSpring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFluxEPSS 0.3%CVE-2026-40978HIGHSQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs.EPSS 0.3%CVE-2026-22731HIGHAuthentication Bypass under Actuator Health groups pathsEPSS 0.3%CVE-2026-59284MEDIUMSpring Cloud Commons no allow list for writable env actuator endpointEPSS 0.3%CVE-2026-40988HIGHUnbounded DEFLATE Inflation in SAML 2.0 Service ProviderEPSS 0.3%CVE-2026-41721MEDIUMSpring Data Commons Denial of Service via Data BindingEPSS 0.3%CVE-2026-41717HIGHSpring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter BindingEPSS 0.3%CVE-2026-47888HIGHSpring Framework Memory Leak via SETUP Frame in RSocketMessageHandlerEPSS 0.3%CVE-2026-59282HIGHSpring Framework Denial of Service via Unbounded List Growth in Data BindingEPSS 0.3%CVE-2026-59271MEDIUMAdmin password disclosed in BrokerNotAliveException messageEPSS 0.3%CVE-2026-47886HIGHSpring Framework Denial of Service via Unbounded Exponentiation in SpEL ExpressionsEPSS 0.3%CVE-2026-47894MEDIUMSpring Cloud Config Server Native Environment Repository ExposureEPSS 0.3%CVE-2026-41848LOWSpring Framework Denial of Service via AntPathMatcherEPSS 0.3%CVE-2026-47890CRITICALSpring Framework Server Sent Event stream corruption while rendering fragmentsEPSS 0.3%CVE-2026-40975MEDIUMValues produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} shoEPSS 0.3%CVE-2025-22232MEDIUMSpring Cloud Config Server May Not Use Vault Token Sent By ClientsEPSS 0.3%CVE-2026-41728HIGHSpring Data REST JSON Patch bypasses Jackson read-only property protection on nested objects and collectionsEPSS 0.3%CVE-2026-47835HIGHSpring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector StoresEPSS 0.3%CVE-2026-41711MEDIUMPotential Denial of Service through crafted Sort ParametersEPSS 0.3%CVE-2026-41007HIGHSpring HATEOAS heap exhaustion through unbounded internal cachingEPSS 0.3%