Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Spring Boot — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Spring Boot, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations related to the Spring Boot framework developed by VMware. It compiles vulnerability data to assist security professionals in assessing risks associated with this widely used Java-based development platform. The content covers various vulnerability types, including injection flaws, insecure configurations, and path traversal issues, spanning from the framework's initial public releases through the most recent updates. Visitors can utilize this resource to track vendor advisories and monitor security patches issued by VMware for Spring Boot components. The page also enables users to understand the prevalence and characteristics of specific weakness classes within the Spring ecosystem. Additionally, users can look up the product's vulnerability history to identify trends and recurring security patterns over time. This aggregation aims to provide a comprehensive view of the security landscape for Spring Boot, helping developers and system administrators prioritize remediation efforts. By centralizing this information, the page facilitates informed decision-making regarding software maintenance and risk management. The data is organized to support both high-level overviews and detailed technical investigations into specific vulnerabilities. This approach ensures that stakeholders have access to critical security insights without needing to sift through disparate sources. The goal is to enhance transparency and support proactive security practices within the Java development community.

Vendor: Dell EMC

CVE ID Title CVSS Severity Published
CVE-2026-41001 Predictable Temp Directory in Artemis Auto-configuration CWE-377 5.3 Medium 2026-06-11
CVE-2026-40992 Mail Auto-Configuration Does Not Enable SSL Hostname Verification CWE-295 5.0 Medium 2026-06-11
CVE-2026-40977 VMware Spring Boot 后置链接漏洞 CWE-59 4.7 Medium 2026-04-27
CVE-2026-40976 VMware Spring Boot 安全漏洞 CWE-862 9.1 Critical 2026-04-27
CVE-2026-40975 VMware Spring Boot 安全特征问题漏洞 CWE-330 4.8 Medium 2026-04-27
CVE-2026-40974 VMware Spring Boot 信任管理问题漏洞 CWE-295 5.0 Medium 2026-04-27
CVE-2026-40973 VMware Spring Boot 安全漏洞 CWE-377 7.0 High 2026-04-27
CVE-2026-40972 VMware Spring Boot 安全漏洞 CWE-208 7.5 High 2026-04-27
CVE-2026-40971 VMware Spring Boot 信任管理问题漏洞 CWE-295 5.0 Medium 2026-04-27
CVE-2026-40970 VMware Spring Boot 信任管理问题漏洞 CWE-295 5.0 Medium 2026-04-27
CVE-2026-22731 Authentication Bypass under Actuator Health groups paths CWE-288 8.2 High 2026-03-19
CVE-2025-22235 Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed CWE-20 7.3 High 2025-04-28
CVE-2024-38807 CVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's Loader 6.3 Medium 2024-08-23
CVE-2023-34055 Spring Boot server Web Observations DoS Vulnerability 5.3 Medium 2023-11-28
CVE-2023-20883 Spring Framework 资源管理错误漏洞 CWE-400 7.5 - 2023-05-26
CVE-2023-20873 Spring Framework 安全漏洞 9.8 - 2023-04-20
CVE-2019-3797 Additional information exposure with Spring Data JPA derived queries CWE-89 5.3 - 2019-05-06
CVE-2018-1196 Pivotal Spring Boot 安全漏洞 6.5 - 2018-03-19

All 18 known CVE vulnerabilities affecting Spring Boot with full Chinese analysis, references, and POCs where available.