Vulnerabilidades em Spring

247 resultados
Análise Vexday

O ecossistema Spring acumula 149 CVEs catalogadas, com um volume expressivo de 98 vulnerabilidades surgidas nos últimos 90 dias, o que indica ritmo elevado de descoberta recente e demanda atenção contínua no processo de atualização. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhuma CVE confirmada em uso por atores maliciosos no momento, embora a presença de 8 vulnerabilidades com PoC pública e 7 de severidade crítica represente superfície de risco relevante. O tipo de falha mais frequente é CWE-400 (consumo descontrolado de recursos), sugerindo que controles de limitação de entrada e de recursos devem ser priorizados nas revisões de configuração. A CVE mais perigosa identificada é CVE-2020-5398, com score EPSS de 0,88, indicando alta probabilidade estatística de exploração — ambientes que ainda não aplicaram a correção correspondente devem tratá-la com urgência.

CVE-2026-40976CRITICALIn certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an applicatioEPSS 0.5%CVE-2025-22223MEDIUMSpring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authEPSS 0.5%CVE-2026-59285HIGHSpring for GraphQL Unsafe Deserialization in pagination supportEPSS 0.5%CVE-2023-34036MEDIUMForwarded header exploit with Spring HATEOAS on WebFluxEPSS 0.5%CVE-2024-38810MEDIUMMissing Authorization When Using @AuthorizeReturnObjectEPSS 0.5%CVE-2026-40981HIGHWhen using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentiaEPSS 0.4%CVE-2026-41699HIGHUnsafe Deserialization in Spring GraphQLEPSS 0.4%CVE-2026-47884CRITICALSpring Framework Improper Path Limitation in XsltViewEPSS 0.4%CVE-2023-34047LOWExposure of data and identity to wrong session in Spring for GraphQLEPSS 0.4%CVE-2025-22233LOWSpring Framework DataBinder Case Sensitive Match ExceptionEPSS 0.4%CVE-2025-22235HIGHSpring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposedEPSS 0.4%CVE-2026-41842HIGHSpring Framework Denial of Service via Versioned Resources in Spring MVC and WebFluxEPSS 0.4%CVE-2026-41863MEDIUMLLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills APIEPSS 0.4%CVE-2025-22234MEDIUMSpring Security - BCrypt Password Encoder maximum password length breaks timing attack mitigationEPSS 0.4%CVE-2026-40967HIGHIn Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector storEPSS 0.4%CVE-2026-41729HIGHSpring Data REST SpEL Injection via Map Key in JSON PatchEPSS 0.4%CVE-2026-59313CRITICALServer Sent Event stream corruption in Spring MVC functional web frameworkEPSS 0.4%CVE-2026-59279HIGHUnbounded persistent session allocation via repeated initialize requestsEPSS 0.4%CVE-2026-22737MEDIUMSpring Framework Improper Path Limitation with Script View TemplatesEPSS 0.4%CVE-2026-40999HIGHSpring WS SSRF via unvalidated WS-Addressing reply destinationsEPSS 0.4%