All 5 CVE vulnerabilities found in Spring Batch, with AI-generated Chinese analysis, references, and POCs.
Vendor: Spring
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-47881 | Denial of Service in Spring Batch FlatFileItemReader via Malformed Input File | 5.9 | Medium | 2026-08-27 |
| CVE-2026-47878 | Unsafe Java deserialization in DefaultExecutionContextSerializer without class allowlist | 5.6 | Medium | 2026-08-27 |
| CVE-2026-47875 | JobParameterDeserializer bypasses the trusted-type allowlist | 5.6 | Medium | 2026-08-27 |
| CVE-2020-5411 | Jackson Configuration Allows Code Execution with Unknown "Serialization Gadgets" CWE-502 | 9.8 | - | 2020-06-11 |
| CVE-2019-3774 | Spring Batch XML External Entity Injection (XXE) CWE-611 | 9.8 | - | 2019-01-18 |
All 5 known CVE vulnerabilities affecting Spring Batch with full Chinese analysis, references, and POCs where available.