以下是该漏洞描述的中文翻译: 漏洞描述翻译: 使用视图片段(view fragments)结合服务器发送事件(Server-Sent Events, SSE)时,Spring MVC 和 Spring WebFlux 应用程序存在流损坏(stream corruption)漏洞。 受影响的版本范围: Spring Framework 7.0.0 至 7.0.8 Spring Framework 6.2.0 至 6.2.19 术语说明: Stream corruption:流损坏,指在 SSE 响应流处理过程中,由于
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Spring | Spring Framework | 7.0.0 ~ 7.0.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59270 | 9.4 CRITICAL | Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN o |
| CVE-2026-47877 | 8.2 HIGH | Spring Security Authorization Server Default Consent Page is vulnerable to Cross-Site Scri |
| CVE-2026-47879 | 7.7 HIGH | Spring Cloud Gateway SSRF and native file access with gRPC |
| CVE-2026-47849 | 7.1 HIGH | Spring Data REST allows mutation of identifier and version properties via JSON Patch |
| CVE-2026-59275 | 6.6 MEDIUM | Remote JVM termination: nested-array Java deserialization bypasses allowlist, triggers Sta |
| CVE-2026-59274 | 6.5 MEDIUM | Unbounded decompression in UnZipTransformer enables zip-bomb DoS |
| CVE-2026-59278 | 6.5 MEDIUM | In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types |
| CVE-2026-47864 | 6.4 MEDIUM | Unsafe Java deserialization in SerializingHttpMessageConverter — remote code execution |
| CVE-2026-47881 | 5.9 MEDIUM | Denial of Service in Spring Batch FlatFileItemReader via Malformed Input File |
| CVE-2026-47875 | 5.6 MEDIUM | JobParameterDeserializer bypasses the trusted-type allowlist |
| CVE-2026-47878 | 5.6 MEDIUM | Unsafe Java deserialization in DefaultExecutionContextSerializer without class allowlist |
| CVE-2026-47880 | 5.4 MEDIUM | DefaultJmsHeaderMapper copies all JMS user properties into MessageHeaders without excludin |
| CVE-2026-59271 | 5.3 MEDIUM | Admin password disclosed in BrokerNotAliveException message |
| CVE-2026-47894 | 4.9 MEDIUM | Spring Cloud Config Server Native Environment Repository Exposure |
| CVE-2026-47892 | Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints | |
| CVE-2026-47885 | Spring Framework maxPartSize Ignored in PartEventHttpMessageReader | |
| CVE-2026-47891 | Spring Framework maxInMemorySize Bypassed in Jaxb2Decoder | |
| CVE-2026-47889 | Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse | |
| CVE-2026-47887 | Spring Framework Open Redirect in UrlFileNameViewController | |
| CVE-2026-47893 | Spring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketServic |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet