Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Spring Boot — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Spring Boot, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive overview of Common Weakness Enumeration (CWE) vulnerabilities affecting the Spring Boot product, maintained by the Pivotal software vendor. It aggregates reported security flaws and configuration issues that impact the stability, confidentiality, and integrity of applications built with this popular Java framework. The database collects a wide range of vulnerability types, including remote code execution, injection flaws, improper input validation, and cross-site scripting, specifically within the context of Spring Boot components. The information spans a comprehensive time range, covering historical data from the framework's inception through recent releases, ensuring that both legacy and modern instances are accounted for. This temporal breadth allows for a holistic view of how security postures have evolved alongside the product's frequent updates and feature additions. By utilizing this resource, users can effectively track vendor advisories and security bulletins issued by Pivotal and the broader Spring community. It enables developers and security professionals to deeply understand the specific characteristics and exploitation mechanisms associated with particular weakness classes as they apply to this technology stack. Furthermore, it serves as a vital reference for looking up a product’s vulnerability history, helping teams assess their exposure, prioritize remediation efforts, and implement necessary patches based on real-world data and reported incidents.

Vendor: Dell EMC

CVE IDTitleCVSSSeverityPublished
CVE-2026-41001 Predictable Temp Directory in Artemis Auto-configuration CWE-377 5.3 Medium2026-06-11
CVE-2026-40992 Mail Auto-Configuration Does Not Enable SSL Hostname Verification CWE-295 5.0 Medium2026-06-11
CVE-2026-40977 VMware Spring Boot 后置链接漏洞 CWE-59 4.7 Medium2026-04-27
CVE-2026-40976 VMware Spring Boot 安全漏洞 CWE-862 9.1 Critical2026-04-27
CVE-2026-40975 VMware Spring Boot 安全特征问题漏洞 CWE-330 4.8 Medium2026-04-27
CVE-2026-40974 VMware Spring Boot 信任管理问题漏洞 CWE-295 5.0 Medium2026-04-27
CVE-2026-40973 VMware Spring Boot 安全漏洞 CWE-377 7.0 High2026-04-27
CVE-2026-40972 VMware Spring Boot 安全漏洞 CWE-208 7.5 High2026-04-27
CVE-2026-40971 VMware Spring Boot 信任管理问题漏洞 CWE-295 5.0 Medium2026-04-27
CVE-2026-40970 VMware Spring Boot 信任管理问题漏洞 CWE-295 5.0 Medium2026-04-27
CVE-2026-22731 Authentication Bypass under Actuator Health groups paths CWE-288 8.2 High2026-03-19
CVE-2025-22235 Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed CWE-20 7.3 High2025-04-28
CVE-2024-38807 CVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's Loader 6.3 Medium2024-08-23
CVE-2023-34055 Spring Boot server Web Observations DoS Vulnerability 5.3 Medium2023-11-28
CVE-2023-20883 Spring Framework 资源管理错误漏洞 CWE-400 7.5 -2023-05-26
CVE-2023-20873 Spring Framework 安全漏洞 9.8 -2023-04-20
CVE-2019-3797 Additional information exposure with Spring Data JPA derived queries CWE-89 5.3 -2019-05-06
CVE-2018-1196 Pivotal Spring Boot 安全漏洞 6.5 -2018-03-19

All 18 known CVE vulnerabilities affecting Spring Boot with full Chinese analysis, references, and POCs where available.