Vulnerabilidades en Spring

247 resultados
Análisis Vexday

O ecossistema Spring acumula 149 CVEs catalogadas, com um volume expressivo de 98 vulnerabilidades surgidas nos últimos 90 dias, o que indica ritmo elevado de descoberta recente e demanda atenção contínua no processo de atualização. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhuma CVE confirmada em uso por atores maliciosos no momento, embora a presença de 8 vulnerabilidades com PoC pública e 7 de severidade crítica represente superfície de risco relevante. O tipo de falha mais frequente é CWE-400 (consumo descontrolado de recursos), sugerindo que controles de limitação de entrada e de recursos devem ser priorizados nas revisões de configuração. A CVE mais perigosa identificada é CVE-2020-5398, com score EPSS de 0,88, indicando alta probabilidade estatística de exploração — ambientes que ainda não aplicaram a correção correspondente devem tratá-la com urgência.

CVE-2026-59303LOWDynamic destination cache size is not properly bound in Spring Cloud StreamEPSS 0.2%CVE-2026-59302LOWPotential for logging sensitive data in Spring Cloud StreamEPSS 0.1%CVE-2026-47844MEDIUMReactor Netty HTTP Server Leaks Exception DetailsEPSS 0.1%CVE-2026-40995MEDIUMX.509 authentication bypasses Spring Security account checksEPSS 0.1%CVE-2026-41694LOWSAML Payloads Decrypted Without Valid SignatureEPSS 0.1%CVE-2026-41844MEDIUMSpring Framework Open Redirect in Spring MVC and WebFluxEPSS 0.1%CVE-2026-59292LOWWorld-readable metadata file in PropertiesPersistingMetadataStore (insecure temp-file permissions)EPSS 0.1%CVE-2026-47836HIGHSpring Cloud Config Server Susceptible To TOCTOU Attack When Using SVNEPSS 0.1%CVE-2026-47825HIGHSpring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situationsEPSS 0.1%CVE-2026-40970MEDIUMWhen configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting EPSS 0.1%CVE-2026-40973HIGHA local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.seEPSS 0.1%CVE-2026-47838MEDIUMUnauthorized User Impersonation when Using X.509 Client CertificatesEPSS 0.1%CVE-2026-41714MEDIUMIn Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManagerEPSS 0.1%CVE-2026-40996MEDIUMInbound WS-Security allows RSA PKCS#1 v1.5 key transport by defaultEPSS 0.1%CVE-2026-59321MEDIUMShared JSR-223 ScriptEngine evaluated concurrently without THREADING checkEPSS 0.1%CVE-2026-40992MEDIUMMail Auto-Configuration Does Not Enable SSL Hostname VerificationEPSS 0.1%CVE-2026-22751MEDIUMSpring Security JdbcOneTimeTokenService allows a one-time token to authenticate multiple sessionsEPSS 0.1%CVE-2026-41854MEDIUMSpring Framework Server-Side Request Forgery via UriComponentsBuilderEPSS 0.1%CVE-2024-38807MEDIUMCVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's LoaderEPSS 0.1%CVE-2026-22735LOWServer Sent Event stream corruptionEPSS 0.1%