Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Spring Framework — Vulnerabilities & Security Advisories 78

All 78 CVE vulnerabilities found in Spring Framework, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting Spring Framework, a widely-used Java application framework maintained by VMware and now Spring.io. It collects reported defects and associated advisories for this specific product, covering historical and recent disclosures within the tracked time range. Readers can use this interface to monitor new security advisories issued by the vendor, understand the prevalence of specific weakness classes, and review the complete vulnerability history for Spring Framework.

Vendor: Pivotal

CVE ID Title CVSS Severity Published
CVE-2026-59314 Spring Framework response splitting in ContentDisposition - - 2026-08-27
CVE-2026-59313 Server Sent Event stream corruption in Spring MVC functional web framework - - 2026-08-27
CVE-2026-59283 Spring Framework Safety Guard Bypass via SpEL Expression Compilation - - 2026-08-27
CVE-2026-59282 Spring Framework Denial of Service via Unbounded List Growth in Data Binding - - 2026-08-27
CVE-2026-59281 Spring Framework Cross-site Scripting via EscapedErrors - - 2026-08-27
CVE-2026-59280 Spring Framework Path Traversal via Backslash in SpringTemplateLoader - - 2026-08-27
CVE-2026-47893 Spring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketService - - 2026-08-27
CVE-2026-47892 Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints - - 2026-08-27
CVE-2026-47891 Spring Framework maxInMemorySize Bypassed in Jaxb2Decoder - - 2026-08-27
CVE-2026-47890 Spring Framework Server Sent Event stream corruption while rendering fragments - - 2026-08-27
CVE-2026-47889 Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse - - 2026-08-27
CVE-2026-47888 Spring Framework Memory Leak via SETUP Frame in RSocketMessageHandler - - 2026-08-27
CVE-2026-47887 Spring Framework Open Redirect in UrlFileNameViewController - - 2026-08-27
CVE-2026-47886 Spring Framework Denial of Service via Unbounded Exponentiation in SpEL Expressions - - 2026-08-27
CVE-2026-47885 Spring Framework maxPartSize Ignored in PartEventHttpMessageReader - - 2026-08-27
CVE-2026-47884 Spring Framework Improper Path Limitation in XsltView - - 2026-08-27
CVE-2026-47883 Spring Framework Open Redirect in UrlHandlerFilter - - 2026-08-27
CVE-2026-41855 Spring Framework Unsafe Deserialization via Jackson JMS Converters CWE-502 8.1 High 2026-06-09
CVE-2026-41854 Spring Framework Server-Side Request Forgery via UriComponentsBuilder CWE-918 4.2 Medium 2026-06-09
CVE-2026-41853 Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux CWE-444 5.3 Medium 2026-06-09
CVE-2026-41852 Spring Framework Arbitrary Method Invocation in SpEL Expressions CWE-863 3.7 Low 2026-06-09
CVE-2026-41851 Spring Framework Denial of Service via Unbounded Cache in SpEL CWE-770 5.3 Medium 2026-06-09
CVE-2026-41850 Spring Framework Algorithmic Denial of Service via SpEL Expressions CWE-407 7.5 High 2026-06-09
CVE-2026-41849 Spring Framework Denial of Service via Integer Overflow in SpEL Expressions CWE-190 7.5 High 2026-06-09
CVE-2026-41848 Spring Framework Denial of Service via AntPathMatcher CWE-1333 3.7 Low 2026-06-09
CVE-2026-41847 Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL CWE-284 4.8 Medium 2026-06-09
CVE-2026-41846 Spring Framework Cross-site Scripting via JSP Form Tags CWE-79 5.9 Medium 2026-06-09
CVE-2026-41845 Spring Framework Cross-site Scripting via JavaScriptUtils CWE-79 7.1 High 2026-06-09
CVE-2026-41844 Spring Framework Open Redirect in Spring MVC and WebFlux CWE-601 4.2 Medium 2026-06-09
CVE-2026-41843 Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux CWE-22 5.9 Medium 2026-06-09

All 78 known CVE vulnerabilities affecting Spring Framework with full Chinese analysis, references, and POCs where available.