Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-47882— Spring Boot DevTools remote secret generated with a non-cryptographic PRNG

CVSS 8.3 · High EPSS 0.17% · P7

Affected Version Matrix 1

VendorProductVersion RangeStatus
SpringSpring Tools for Eclipse≤ 5.2.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-47882

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Spring Boot DevTools remote secret generated with a non-cryptographic PRNG
Source: CVE Program / CVE List V5
Vulnerability Description
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Spring Tools for Eclipse 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Spring Spring Tools for Eclipse是美国Spring公司开源的一套软件开发工具插件。 Spring Tools for Eclipse 5.2.0及之前版本存在加密问题漏洞,该漏洞源于使用非加密的伪随机数生成器生成共享密钥,导致远程重启上传的身份验证不充分。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
SpringSpring Tools for Eclipse 0 ~ 5.2.0 -

II. Public POCs for CVE-2026-47882

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-47882

登录查看更多情报信息。

Vendor Advisories for CVE-2026-47882 (1)

Same Patch Batch · Spring · 2026-07-30 · 6 CVEs total

CVE-2026-478588.0 HIGHlive information startup mode is vulnerable for remote code execution
CVE-2026-478738.0 HIGHSpring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on al
CVE-2026-593274.4 MEDIUMCleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations
CVE-2026-593284.2 MEDIUMCross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips
CVE-2026-593263.3 LOWHTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server

IV. Related Vulnerabilities

V. Comments for CVE-2026-47882

No comments yet


Leave a comment