使用 时,若通过双参数构造函数创建实例,或在 CBC 加密模式下传入空的 IV 生成器(null IV generator),则数据将使用 AES/CBC 模式进行加密,且初始化向量(IV)为全零(null/all-zero)。 受影响的 Spring Security 版本: Spring Security 7.1.0 Spring Security 7.0.0 – 7.0.6 Spring Security 6.5.0 – 6.5.11 Spring Security 6.4.0 – 6.4.18 Spring
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Security | 7.1.0 |
affected |
7.0.0≤ 7.0.6 |
affected | ||
6.5.0≤ 6.5.11 |
affected | ||
6.4.0≤ 6.4.18 |
affected | ||
5.8.0≤ 5.8.27 |
affected | ||
5.7.0≤ 5.7.25 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Spring | Spring Security | 7.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47852 | 7.5 HIGH | Predictable cache directory location allows local ONNX model substitution in Spring AI |
| CVE-2026-47851 | 7.5 HIGH | Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Re |
| CVE-2026-47841 | 7.4 HIGH | WebAuthn User Verification Bypass via Session Serialization |
| CVE-2026-47836 | 7.2 HIGH | Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN |
| CVE-2026-47837 | 6.8 MEDIUM | Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests |
| CVE-2026-47860 | 6.5 MEDIUM | Unbounded decompression of attacker-supplied compressed message bodies |
| CVE-2026-47861 | 6.3 MEDIUM | UDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when ac |
| CVE-2026-47856 | 6.3 MEDIUM | JsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class w |
| CVE-2026-47848 | 6.1 MEDIUM | Reactor Netty WebSocket Client Leaks Credentials On Redirect |
| CVE-2026-47863 | 5.9 MEDIUM | Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream deli |
| CVE-2026-47857 | 5.9 MEDIUM | Reactor Core windowTimeout fair-backpressure stream hang due to 20-bit index wrap-around |
| CVE-2026-47862 | 5.4 MEDIUM | ZipTransformer uses file_name header to build workDirectory path without sanitization |
| CVE-2026-47859 | 5.4 MEDIUM | Unbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote |
| CVE-2026-47844 | 5.3 MEDIUM | Reactor Netty HTTP Server Leaks Exception Details |
| CVE-2026-47845 | 5.3 MEDIUM | Reactor Netty HTTP Server may incorrectly evaluate proxy addresses |
| CVE-2026-47874 | 5.3 MEDIUM | Reactor Netty HTTP Server Denial of Service With Pipelined Requests |
| CVE-2026-47834 | 4.8 MEDIUM | Spring Data JPA Sort expression validation bypass |
| CVE-2026-47850 | 4.3 MEDIUM | Spring Data REST allows mutation of the version property of immutable aggregates via PUT |
| CVE-2026-47843 | 3.7 LOW | Reactor Netty may incorrectly route traffic due to DNS resolver reuse |
No comments yet