Vulnerabilidades en spring

247 resultados
Análisis Vexday

Spring apresenta 1 CVE na base Vexday, sem ocorrências de ataque ativo documentado (KEV). A vulnerabilidade é relacionada a falha em autenticação (CWE-287) e não foi publicada nos últimos 90 dias, indicando risco estável e consolidado.

CVE-2026-59319MEDIUMRediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data ExposureEPSS 0.2%CVE-2026-40987HIGHRemote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalizationEPSS 0.2%CVE-2026-22746LOWUser Attribute Enumeration when Using DaoAuthenticationProviderEPSS 0.2%CVE-2026-41839MEDIUMSpring Framework Escalation via Session Fixation in WebFluxEPSS 0.2%CVE-2026-41706MEDIUMOpen Redirect When Using CookieRequestCacheEPSS 0.2%CVE-2026-40990MEDIUMUnbounded cache for function definitionsEPSS 0.2%CVE-2026-59322MEDIUMEmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeadersEPSS 0.2%CVE-2026-40989MEDIUMSelf Routing guard bypassed via function compositionEPSS 0.2%CVE-2026-59277LOWSpring Security InetAddressMatchers Incomplete Internal Network ClassificationEPSS 0.2%CVE-2026-47858HIGHlive information startup mode is vulnerable for remote code executionEPSS 0.2%CVE-2026-40986MEDIUMSpring Web Flow JS RemotingHandler renders non-HTML Response as HTMLEPSS 0.2%CVE-2026-41719MEDIUMSpring Data KeyValue - SpEL Injection vulnerability in SpelPropertyComparatorEPSS 0.2%CVE-2026-47834MEDIUMSpring Data JPA Sort expression validation bypassEPSS 0.2%CVE-2026-41003HIGHUnencoded HTML Outputs in Spring Security May Allow Cross-Site ScriptingEPSS 0.2%CVE-2026-22748MEDIUMPotential Security Misconfiguration when Using withIssuerLocationEPSS 0.2%CVE-2026-47852HIGHPredictable cache directory location allows local ONNX model substitution in Spring AIEPSS 0.2%CVE-2026-40969LOWSpring gRPC AuthenticationException message reflected to remote clientEPSS 0.2%CVE-2026-59314LOWSpring Framework response splitting in ContentDispositionEPSS 0.2%CVE-2026-40993HIGHUnfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database EntryEPSS 0.2%CVE-2026-41730MEDIUMSpring Data REST exposes persistence-layer internals in error responsesEPSS 0.2%