Vulnerabilidades em Spring

247 resultados
Análise Vexday

O ecossistema Spring acumula 149 CVEs catalogadas, com um volume expressivo de 98 vulnerabilidades surgidas nos últimos 90 dias, o que indica ritmo elevado de descoberta recente e demanda atenção contínua no processo de atualização. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhuma CVE confirmada em uso por atores maliciosos no momento, embora a presença de 8 vulnerabilidades com PoC pública e 7 de severidade crítica represente superfície de risco relevante. O tipo de falha mais frequente é CWE-400 (consumo descontrolado de recursos), sugerindo que controles de limitação de entrada e de recursos devem ser priorizados nas revisões de configuração. A CVE mais perigosa identificada é CVE-2020-5398, com score EPSS de 0,88, indicando alta probabilidade estatística de exploração — ambientes que ainda não aplicaram a correção correspondente devem tratá-la com urgência.

CVE-2026-22739HIGHSpring Cloud Config Profile Substitution Can Allow Unintended Access To Files And Enable SSRF AttacksEPSS 1.2%CVE-2023-34055MEDIUMSpring Boot server Web Observations DoS VulnerabilityEPSS 1.2%CVE-2024-22262HIGHCVE-2024-22262: Spring Framework URL Parsing with Host ValidationEPSS 1.2%CVE-2023-34053MEDIUMSpring Framework server Web Observations DoS VulnerabilityEPSS 1.2%CVE-2026-22738CRITICALSpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code ExecutionEPSS 1.1%CVE-2019-3797LOWAdditional information exposure with Spring Data JPA derived queriesEPSS 1.1%CVE-2024-22233HIGHCVE-2024-22233: Spring Framework server Web DoS VulnerabilityEPSS 1.0%CVE-2023-34054MEDIUMReactor Netty HTTP Server Metrics DoS VulnerabilityEPSS 0.9%CVE-2026-40984HIGHMicrometer HTTP server instrumentations DoS vulnerabilityEPSS 0.8%CVE-2026-41862HIGHSpring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts withoEPSS 0.7%CVE-2026-40982CRITICALSpring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious EPSS 0.7%CVE-2024-38828MEDIUMCVE-2024-38828: DoS via Spring MVC controller method with byte[] parameterEPSS 0.7%CVE-2024-22234HIGHCVE-2024-22234: Broken Access Control in Spring Security With Direct Use of isFullyAuthenticatedEPSS 0.7%CVE-2026-40983HIGHMicrometer gRPC server instrumentation DoS vulnerabilityEPSS 0.6%CVE-2025-41232CRITICALCVE-2025-41232: Spring Security authorization bypass for method security annotations on private methodsEPSS 0.6%CVE-2025-22228HIGHCVE-2025-22228: Spring Security BCryptPasswordEncoder does not enforce maximum password lengthEPSS 0.6%CVE-2026-22718MEDIUMCommand injection vulnerabilityEPSS 0.6%CVE-2024-38808MEDIUMCVE-2024-38808: Spring Expression DoS VulnerabilityEPSS 0.6%CVE-2024-22258MEDIUMCVE-2024-22258: PKCE Downgrade in Spring Authorization ServerEPSS 0.5%CVE-2026-41731HIGHIn Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserializationEPSS 0.5%