Vulnerabilities in spring
247 resultsVexday analysis
Spring apresenta 1 CVE na base Vexday, sem ocorrências de ataque ativo documentado (KEV). A vulnerabilidade é relacionada a falha em autenticação (CWE-287) e não foi publicada nos últimos 90 dias, indicando risco estável e consolidado.
CVE-2026-47851HIGHUnbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document ReaderEPSS 0.3%CVE-2026-40972HIGHAn attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote seEPSS 0.3%CVE-2026-41696MEDIUMSpring Data MongoDB Bind Parameter Literal Quoting BreakoutEPSS 0.3%CVE-2026-59294MEDIUMArbitrary File Write via Path Traversal in ResourceCacheServiceEPSS 0.3%CVE-2026-47885HIGHSpring Framework maxPartSize Ignored in PartEventHttpMessageReaderEPSS 0.3%CVE-2026-59276MEDIUMTiming Attack via Non-Constant-Time Comparison of Sensitive ValuesEPSS 0.3%CVE-2026-41720HIGHAuthentication Bypass with Empty Password in Spring LDAPEPSS 0.3%CVE-2026-47878MEDIUMUnsafe Java deserialization in DefaultExecutionContextSerializer without class allowlistEPSS 0.3%CVE-2026-47862MEDIUMZipTransformer uses file_name header to build workDirectory path without sanitizationEPSS 0.3%CVE-2026-41707HIGHSpring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof ReplayEPSS 0.3%CVE-2026-47889HIGHSpring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponseEPSS 0.3%CVE-2026-47861MEDIUMUDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when acknowledge=falseEPSS 0.3%CVE-2026-22744HIGHIn RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, strinEPSS 0.3%CVE-2026-22743HIGHServer-Side Request Forgery via Filter Expression Keys in Neo4jVectorStoreEPSS 0.3%CVE-2026-47879HIGHSpring Cloud Gateway SSRF and native file access with gRPCEPSS 0.3%CVE-2026-22753HIGHServlet Path Not Correctly Included in Path Matching of HttpSecurity#securityMatchersEPSS 0.2%CVE-2026-59275MEDIUMRemote JVM termination: nested-array Java deserialization bypasses allowlist, triggers StackOverflowError, default JavaLangErrorHandler calls System.exit(99)EPSS 0.2%CVE-2026-59286HIGHSpring for GraphQL loads Untrusted Resources in GraphiQL supportEPSS 0.2%CVE-2026-47893HIGHSpring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketServiceEPSS 0.2%CVE-2026-47856MEDIUMJsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-listEPSS 0.2%