Vulnerabilidades em Spring

247 resultados
Análise Vexday

O ecossistema Spring acumula 149 CVEs catalogadas, com um volume expressivo de 98 vulnerabilidades surgidas nos últimos 90 dias, o que indica ritmo elevado de descoberta recente e demanda atenção contínua no processo de atualização. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, com nenhuma CVE confirmada em uso por atores maliciosos no momento, embora a presença de 8 vulnerabilidades com PoC pública e 7 de severidade crítica represente superfície de risco relevante. O tipo de falha mais frequente é CWE-400 (consumo descontrolado de recursos), sugerindo que controles de limitação de entrada e de recursos devem ser priorizados nas revisões de configuração. A CVE mais perigosa identificada é CVE-2020-5398, com score EPSS de 0,88, indicando alta probabilidade estatística de exploração — ambientes que ainda não aplicaram a correção correspondente devem tratá-la com urgência.

CVE-2026-59319MEDIUMRediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data ExposureEPSS 0.2%CVE-2026-40987HIGHRemote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalizationEPSS 0.2%CVE-2026-22746LOWUser Attribute Enumeration when Using DaoAuthenticationProviderEPSS 0.2%CVE-2026-41839MEDIUMSpring Framework Escalation via Session Fixation in WebFluxEPSS 0.2%CVE-2026-41706MEDIUMOpen Redirect When Using CookieRequestCacheEPSS 0.2%CVE-2026-40990MEDIUMUnbounded cache for function definitionsEPSS 0.2%CVE-2026-59322MEDIUMEmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeadersEPSS 0.2%CVE-2026-40989MEDIUMSelf Routing guard bypassed via function compositionEPSS 0.2%CVE-2026-59277LOWSpring Security InetAddressMatchers Incomplete Internal Network ClassificationEPSS 0.2%CVE-2026-47858HIGHlive information startup mode is vulnerable for remote code executionEPSS 0.2%CVE-2026-40986MEDIUMSpring Web Flow JS RemotingHandler renders non-HTML Response as HTMLEPSS 0.2%CVE-2026-41719MEDIUMSpring Data KeyValue - SpEL Injection vulnerability in SpelPropertyComparatorEPSS 0.2%CVE-2026-47834MEDIUMSpring Data JPA Sort expression validation bypassEPSS 0.2%CVE-2026-41003HIGHUnencoded HTML Outputs in Spring Security May Allow Cross-Site ScriptingEPSS 0.2%CVE-2026-22748MEDIUMPotential Security Misconfiguration when Using withIssuerLocationEPSS 0.2%CVE-2026-47852HIGHPredictable cache directory location allows local ONNX model substitution in Spring AIEPSS 0.2%CVE-2026-40969LOWSpring gRPC AuthenticationException message reflected to remote clientEPSS 0.2%CVE-2026-59314LOWSpring Framework response splitting in ContentDispositionEPSS 0.2%CVE-2026-40993HIGHUnfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database EntryEPSS 0.2%CVE-2026-41730MEDIUMSpring Data REST exposes persistence-layer internals in error responsesEPSS 0.2%