Vulnerabilidades en spring

247 resultados
Análisis Vexday

Spring apresenta 1 CVE na base Vexday, sem ocorrências de ataque ativo documentado (KEV). A vulnerabilidade é relacionada a falha em autenticação (CWE-287) e não foi publicada nos últimos 90 dias, indicando risco estável e consolidado.

CVE-2026-59296MEDIUMMicrometer StatsD and Logging meter registries line-protocol and log injection vulnerabilityEPSS 0.2%CVE-2026-47873HIGHSpring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfacesEPSS 0.2%CVE-2026-41837MEDIUMSpring Data REST Querydsl integration exposes Jackson-hidden persistent fields as filter keysEPSS 0.2%CVE-2026-41700HIGHCross-Site WebSocket Hijacking in Spring for GraphQLEPSS 0.2%CVE-2026-47880MEDIUMDefaultJmsHeaderMapper copies all JMS user properties into MessageHeaders without excluding framework-significant namesEPSS 0.2%CVE-2026-47883MEDIUMSpring Framework Open Redirect in UrlHandlerFilterEPSS 0.2%CVE-2026-41853MEDIUMSpring Framework Multipart Request Smuggling in Spring MVC and WebFluxEPSS 0.2%CVE-2026-59318MEDIUMDefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via Prompt InjectionEPSS 0.2%CVE-2026-59316HIGHSpring Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS)EPSS 0.2%CVE-2026-47850MEDIUMSpring Data REST allows mutation of the version property of immutable aggregates via PUTEPSS 0.2%CVE-2026-40974MEDIUMSpring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. AffecteEPSS 0.2%CVE-2026-59281MEDIUMSpring Framework Cross-site Scripting via EscapedErrorsEPSS 0.2%CVE-2026-41008MEDIUMSpring Security Authorization Server Open Redirect via request_uriEPSS 0.2%CVE-2026-47882HIGHSpring Boot DevTools remote secret generated with a non-cryptographic PRNGEPSS 0.2%CVE-2026-41852LOWSpring Framework Arbitrary Method Invocation in SpEL ExpressionsEPSS 0.2%CVE-2026-47845MEDIUMReactor Netty HTTP Server may incorrectly evaluate proxy addressesEPSS 0.2%CVE-2026-59291LOWPotential arbitrary file read and SSRF vulnerability in Spring Cloud FunctionEPSS 0.2%CVE-2026-41701MEDIUMIn Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queuesEPSS 0.2%CVE-2026-47887MEDIUMSpring Framework Open Redirect in UrlFileNameViewControllerEPSS 0.2%CVE-2026-41715MEDIUMReactor Netty HTTP Client Leaks Credentials On Protocol Downgrade RedirectEPSS 0.2%