Vulnerabilidades en spring

247 resultados
Análisis Vexday

Spring apresenta 1 CVE na base Vexday, sem ocorrências de ataque ativo documentado (KEV). A vulnerabilidade é relacionada a falha em autenticação (CWE-287) e não foi publicada nos últimos 90 dias, indicando risco estável e consolidado.

CVE-2026-40980MEDIUMIn Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayEPSS 0.2%CVE-2026-59274MEDIUMUnbounded decompression in UnZipTransformer enables zip-bomb DoSEPSS 0.2%CVE-2026-47860MEDIUMUnbounded decompression of attacker-supplied compressed message bodiesEPSS 0.2%CVE-2026-41727MEDIUMIn Spring for Apache Kafka, forged retry topic headers subvert retry routing and backoff behaviorEPSS 0.2%CVE-2026-47874MEDIUMReactor Netty HTTP Server Denial of Service With Pipelined RequestsEPSS 0.2%CVE-2026-59324HIGHfluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunctionEPSS 0.2%CVE-2026-59280MEDIUMSpring Framework Path Traversal via Backslash in SpringTemplateLoaderEPSS 0.2%CVE-2026-47863MEDIUMReactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream delivers items during an active flushEPSS 0.2%CVE-2026-40985MEDIUMData Binding Vulnerability in Spring Web Flow with Unified EL ParserEPSS 0.2%CVE-2026-40994HIGHWss4jSecurityInterceptor disables WS-I BSP validation by defaultEPSS 0.2%CVE-2026-59306LOWPotential for deserialization of untrusted types in Spring Cloud StreamEPSS 0.2%CVE-2026-47859MEDIUMUnbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoSEPSS 0.2%CVE-2026-41697MEDIUMSpring Data Relational Parameter not Escaped for Query By Example LIKE PatternEPSS 0.2%CVE-2026-41000LOWWSS4J validation does not use configured replay cacheEPSS 0.2%CVE-2026-40991MEDIUMXML External Entity (XXE) injection when documenting untrusted XML contentEPSS 0.2%CVE-2024-22236LOWIn Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution iEPSS 0.2%CVE-2026-59295MEDIUMMicrometer instrumentation of Apache HttpAsyncClient DoS vulnerabilityEPSS 0.2%CVE-2026-47857MEDIUMReactor Core windowTimeout fair-backpressure stream hang due to 20-bit index wrap-aroundEPSS 0.2%CVE-2026-59293MEDIUMSMB minimum protocol dialect defaults to SMB1EPSS 0.2%CVE-2026-41002HIGHThe base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptEPSS 0.2%