Vulnerabilidades em Spring

247 resultados
Análise Vexday

O ecossistema Spring acumula 149 CVEs catalogadas, com um volume expressivo de 98 vulnerabilidades surgidas nos últimos 90 dias, o que indica ritmo elevado de descoberta recente e demanda atenção contínua no processo de atualização. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhuma CVE confirmada em uso por atores maliciosos no momento, embora a presença de 8 vulnerabilidades com PoC pública e 7 de severidade crítica represente superfície de risco relevante. O tipo de falha mais frequente é CWE-400 (consumo descontrolado de recursos), sugerindo que controles de limitação de entrada e de recursos devem ser priorizados nas revisões de configuração. A CVE mais perigosa identificada é CVE-2020-5398, com score EPSS de 0,88, indicando alta probabilidade estatística de exploração — ambientes que ainda não aplicaram a correção correspondente devem tratá-la com urgência.

CVE-2026-59317MEDIUMIn Spring for Apache Kafka, missing header validation in DeadLetterPublishingRecovererFactory enables denial of service via a poison-pill loopEPSS 0.4%CVE-2026-59283CRITICALSpring Framework Safety Guard Bypass via SpEL Expression CompilationEPSS 0.4%CVE-2026-59323MEDIUMMicrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerabilityEPSS 0.4%CVE-2024-38829LOWSpring LDAP sensitive data exposure for case-sensitive comparisonsEPSS 0.4%CVE-2026-41843MEDIUMSpring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFluxEPSS 0.4%CVE-2026-40997MEDIUMSOAP security faults leak Spring Security account stateEPSS 0.4%CVE-2026-47892CRITICALSpring Framework Header Predicate Bypass in WebFlux Functional EndpointsEPSS 0.4%CVE-2026-41695HIGHDenial of Service in Spring Data Commons Property Path ResolutionEPSS 0.4%CVE-2026-41716HIGHSpring Data web support unbounded negative-result cache keyed on attacker-supplied property namesEPSS 0.4%CVE-2026-41850HIGHSpring Framework Algorithmic Denial of Service via SpEL ExpressionsEPSS 0.4%CVE-2026-41851MEDIUMSpring Framework Denial of Service via Unbounded Cache in SpELEPSS 0.4%CVE-2026-22733HIGHAuthentication Bypass under Actuator CloudFoundry endpointsEPSS 0.4%CVE-2026-41705HIGHSpring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. SprinEPSS 0.4%CVE-2026-22742HIGHServer-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL FetchingEPSS 0.4%CVE-2026-40998HIGHJaxp13 XPath XXE via StreamSource and SAXSourceEPSS 0.4%CVE-2026-41856HIGHSpring GraphQL Annotation Detection VulnerabilityEPSS 0.4%CVE-2026-59311MEDIUMFixed predictable /tmp/ziptransformer work directory enables symlink pre-creationEPSS 0.4%CVE-2026-41732HIGHIn Spring for Apache Pulsar, overly broad trusted-package matching in header mapper exposes JDK classes to deserializationEPSS 0.3%CVE-2026-59289HIGHSpring for GraphQL Denial of Service via pagination supportEPSS 0.3%CVE-2026-59307HIGHDeserialization allow-list silently bypassed: setBeanClassLoader replaces deserializer but mapper keeps stale referenceEPSS 0.3%