Vulnerabilidades em Spring

247 resultados
Análise Vexday

O ecossistema Spring acumula 149 CVEs catalogadas, com um volume expressivo de 98 vulnerabilidades surgidas nos últimos 90 dias, o que indica ritmo elevado de descoberta recente e demanda atenção contínua no processo de atualização. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhuma CVE confirmada em uso por atores maliciosos no momento, embora a presença de 8 vulnerabilidades com PoC pública e 7 de severidade crítica represente superfície de risco relevante. O tipo de falha mais frequente é CWE-400 (consumo descontrolado de recursos), sugerindo que controles de limitação de entrada e de recursos devem ser priorizados nas revisões de configuração. A CVE mais perigosa identificada é CVE-2020-5398, com score EPSS de 0,88, indicando alta probabilidade estatística de exploração — ambientes que ainda não aplicaram a correção correspondente devem tratá-la com urgência.

CVE-2026-47837MEDIUMSpring Cloud Config Server Monitor Endpoint Does Not Validate Webhook RequestsEPSS 0.3%CVE-2026-22747MEDIUMUnauthorized User Impersonation when Using X.509 Client CertificatesEPSS 0.3%CVE-2026-41726MEDIUMIn Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector headerEPSS 0.3%CVE-2026-59320MEDIUMIn Spring AMQP the link credit never replenished on listener exception pathEPSS 0.3%CVE-2026-59315MEDIUMSpring Cloud Config Monitor Denial of ServiceEPSS 0.3%CVE-2026-47875MEDIUMJobParameterDeserializer bypasses the trusted-type allowlistEPSS 0.3%CVE-2026-47891CRITICALSpring Framework maxInMemorySize Bypassed in Jaxb2DecoderEPSS 0.3%CVE-2026-47841HIGHWebAuthn User Verification Bypass via Session SerializationEPSS 0.3%CVE-2026-41855HIGHSpring Framework Unsafe Deserialization via Jackson JMS ConvertersEPSS 0.3%CVE-2026-47881MEDIUMDenial of Service in Spring Batch FlatFileItemReader via Malformed Input FileEPSS 0.3%CVE-2026-41710MEDIUMCache Exhaustion in Stateful Retries leads to Denial of ServiceEPSS 0.3%CVE-2026-41708HIGHSpring Cloud Sleuth instrumentation of Spring TX DoS vulnerabilityEPSS 0.3%CVE-2026-41006HIGHSpring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configurationEPSS 0.3%CVE-2026-59287MEDIUMSpring for GraphQL WebSocket Client Denial of ServiceEPSS 0.3%CVE-2026-47849HIGHSpring Data REST allows mutation of identifier and version properties via JSON PatchEPSS 0.3%CVE-2026-59270CRITICALSpring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfacesEPSS 0.3%CVE-2026-59288HIGHSpring for GraphQL Information Exposure in GraphiQL supportEPSS 0.3%CVE-2026-41840MEDIUMSpring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring EPSS 0.3%CVE-2026-22754HIGHervlet Path Not Correctly Included in Path Matching of XML Authorization RulesEPSS 0.3%CVE-2026-47851HIGHUnbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document ReaderEPSS 0.3%