Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Spring Framework — Vulnerabilities & Security Advisories 61

All 61 CVE vulnerabilities found in Spring Framework, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security weaknesses and vulnerabilities associated with the Spring Framework product developed by Pivotal Software, Inc. It focuses on common weakness categories such as remote code execution, broken access control, and security misconfiguration that have been identified in this specific software stack. The content on this page aggregates vulnerability data ranging from early 2002 up to the present day. It includes information about disclosed security issues affecting Spring Framework and its subprojects, providing a comprehensive historical view of security incidents. By examining these records, users can gain insight into the evolution of security threats targeting this widely used enterprise Java framework. Visitors to this page can track vendor advisories and understand the context behind specific weakness classes as they apply to Spring Framework. You can look up a product's vulnerability history to assess risk exposure and identify trends in reported security flaws. This resource serves as a central reference point for security researchers, developers, and risk analysts seeking detailed information about past and present vulnerabilities in the Spring ecosystem. The aim is to provide factual, structured data to support informed decision-making regarding software updates and patch management strategies.

Vendor: Pivotal

CVE ID Title CVSS Severity Published
CVE-2026-41855 Spring Framework Unsafe Deserialization via Jackson JMS Converters CWE-502 8.1 High 2026-06-09
CVE-2026-41854 Spring Framework Server-Side Request Forgery via UriComponentsBuilder CWE-918 4.2 Medium 2026-06-09
CVE-2026-41853 Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux CWE-444 5.3 Medium 2026-06-09
CVE-2026-41852 Spring Framework Arbitrary Method Invocation in SpEL Expressions CWE-863 3.7 Low 2026-06-09
CVE-2026-41851 Spring Framework Denial of Service via Unbounded Cache in SpEL CWE-770 5.3 Medium 2026-06-09
CVE-2026-41850 Spring Framework Algorithmic Denial of Service via SpEL Expressions CWE-407 7.5 High 2026-06-09
CVE-2026-41849 Spring Framework Denial of Service via Integer Overflow in SpEL Expressions CWE-190 7.5 High 2026-06-09
CVE-2026-41848 Spring Framework Denial of Service via AntPathMatcher CWE-1333 3.7 Low 2026-06-09
CVE-2026-41847 Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL CWE-284 4.8 Medium 2026-06-09
CVE-2026-41846 Spring Framework Cross-site Scripting via JSP Form Tags CWE-79 5.9 Medium 2026-06-09
CVE-2026-41845 Spring Framework Cross-site Scripting via JavaScriptUtils CWE-79 7.1 High 2026-06-09
CVE-2026-41844 Spring Framework Open Redirect in Spring MVC and WebFlux CWE-601 4.2 Medium 2026-06-09
CVE-2026-41843 Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux CWE-22 5.9 Medium 2026-06-09
CVE-2026-41842 Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux CWE-400 7.5 High 2026-06-09
CVE-2026-41841 Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux CWE-524 5.9 Medium 2026-06-09
CVE-2026-41840 Spring Framework 资源管理错误漏洞 CWE-401 5.9 Medium 2026-06-09
CVE-2026-41839 Spring Framework Escalation via Session Fixation in WebFlux CWE-384 4.2 Medium 2026-06-09
CVE-2026-41838 Spring Framework Predictable Session ID in WebSocket Module CWE-330 4.8 Medium 2026-06-09
CVE-2026-22745 CVE-2026-22745 : Denial of service in static resource handling on Windows platforms CWE-400 5.3 Medium 2026-04-29
CVE-2026-22741 Static resource cache poisoning in Spring MVC and WebFlux CWE-524 3.1 Low 2026-04-29
CVE-2026-22740 Spring Framework DoS with Multipart Temp Files in WebFlux CWE-400 6.5 Medium 2026-04-29
CVE-2026-22737 Spring Framework Improper Path Limitation with Script View Templates 5.9 Medium 2026-03-19
CVE-2025-41254 Spring Framework STOMP CSRF Vulnerability CWE-352 4.3 Medium 2025-10-16
CVE-2025-41249 CVE-2025-41249: Spring Framework Annotation Detection Vulnerability 7.5 High 2025-09-16
CVE-2025-41242 CVE-2025-41242: Path traversal vulnerability on non-compliant Servlet containers 5.9 Medium 2025-08-18
CVE-2025-41234 RFD Attack via “Content-Disposition” Header Sourced from Request CWE-113 6.5 Medium 2025-06-12
CVE-2025-22233 Spring Framework DataBinder Case Sensitive Match Exception CWE-20 3.1 Low 2025-05-16
CVE-2024-38819 VMware Spring Framework 安全漏洞 CWE-22 7.5 High 2024-12-19
CVE-2024-38809 VMware Spring Framework 安全漏洞 5.3 Medium 2024-09-27
CVE-2024-38808 CVE-2024-38808: Spring Expression DoS Vulnerability 4.3 Medium 2024-08-20

All 61 known CVE vulnerabilities affecting Spring Framework with full Chinese analysis, references, and POCs where available.