Vulnerabilidades em Spring

247 resultados
Análise Vexday

O ecossistema Spring acumula 149 CVEs catalogadas, com um volume expressivo de 98 vulnerabilidades surgidas nos últimos 90 dias, o que indica ritmo elevado de descoberta recente e demanda atenção contínua no processo de atualização. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhuma CVE confirmada em uso por atores maliciosos no momento, embora a presença de 8 vulnerabilidades com PoC pública e 7 de severidade crítica represente superfície de risco relevante. O tipo de falha mais frequente é CWE-400 (consumo descontrolado de recursos), sugerindo que controles de limitação de entrada e de recursos devem ser priorizados nas revisões de configuração. A CVE mais perigosa identificada é CVE-2020-5398, com score EPSS de 0,88, indicando alta probabilidade estatística de exploração — ambientes que ainda não aplicaram a correção correspondente devem tratá-la com urgência.

CVE-2026-41841MEDIUMSpring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFluxEPSS 0.3%CVE-2026-40978HIGHSQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs.EPSS 0.3%CVE-2026-22731HIGHAuthentication Bypass under Actuator Health groups pathsEPSS 0.3%CVE-2026-59284MEDIUMSpring Cloud Commons no allow list for writable env actuator endpointEPSS 0.3%CVE-2026-40988HIGHUnbounded DEFLATE Inflation in SAML 2.0 Service ProviderEPSS 0.3%CVE-2026-41721MEDIUMSpring Data Commons Denial of Service via Data BindingEPSS 0.3%CVE-2026-41717HIGHSpring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter BindingEPSS 0.3%CVE-2026-47888HIGHSpring Framework Memory Leak via SETUP Frame in RSocketMessageHandlerEPSS 0.3%CVE-2026-59282HIGHSpring Framework Denial of Service via Unbounded List Growth in Data BindingEPSS 0.3%CVE-2026-59271MEDIUMAdmin password disclosed in BrokerNotAliveException messageEPSS 0.3%CVE-2026-47886HIGHSpring Framework Denial of Service via Unbounded Exponentiation in SpEL ExpressionsEPSS 0.3%CVE-2026-47894MEDIUMSpring Cloud Config Server Native Environment Repository ExposureEPSS 0.3%CVE-2026-41848LOWSpring Framework Denial of Service via AntPathMatcherEPSS 0.3%CVE-2026-47890CRITICALSpring Framework Server Sent Event stream corruption while rendering fragmentsEPSS 0.3%CVE-2026-40975MEDIUMValues produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} shoEPSS 0.3%CVE-2025-22232MEDIUMSpring Cloud Config Server May Not Use Vault Token Sent By ClientsEPSS 0.3%CVE-2026-41728HIGHSpring Data REST JSON Patch bypasses Jackson read-only property protection on nested objects and collectionsEPSS 0.3%CVE-2026-47835HIGHSpring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector StoresEPSS 0.3%CVE-2026-41711MEDIUMPotential Denial of Service through crafted Sort ParametersEPSS 0.3%CVE-2026-41007HIGHSpring HATEOAS heap exhaustion through unbounded internal cachingEPSS 0.3%