All 6 CVE vulnerabilities found in Spring Tools for Eclipse, with AI-generated Chinese analysis, references, and POCs.
Vendor: Spring
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-59326 | HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server | 3.3 | Low | 2026-07-30 |
| CVE-2026-59328 | Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips | 4.2 | Medium | 2026-07-30 |
| CVE-2026-59327 | Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations | 4.4 | Medium | 2026-07-30 |
| CVE-2026-47882 | Spring Boot DevTools remote secret generated with a non-cryptographic PRNG | 8.3 | High | 2026-07-30 |
| CVE-2026-47873 | Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces | 8.0 | High | 2026-07-30 |
| CVE-2026-47858 | live information startup mode is vulnerable for remote code execution | 8.0 | High | 2026-07-30 |
All 6 known CVE vulnerabilities affecting Spring Tools for Eclipse with full Chinese analysis, references, and POCs where available.