Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Spring Framework — Vulnerabilities & Security Advisories 78

All 78 CVE vulnerabilities found in Spring Framework, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting Spring Framework, a widely-used Java application framework maintained by VMware and now Spring.io. It collects reported defects and associated advisories for this specific product, covering historical and recent disclosures within the tracked time range. Readers can use this interface to monitor new security advisories issued by the vendor, understand the prevalence of specific weakness classes, and review the complete vulnerability history for Spring Framework.

Vendor: Pivotal

CVE ID Title CVSS Severity Published
CVE-2026-41842 Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux CWE-400 7.5 High 2026-06-09
CVE-2026-41841 Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux CWE-524 5.9 Medium 2026-06-09
CVE-2026-41840 Spring Framework 资源管理错误漏洞 CWE-401 5.9 Medium 2026-06-09
CVE-2026-41839 Spring Framework Escalation via Session Fixation in WebFlux CWE-384 4.2 Medium 2026-06-09
CVE-2026-41838 Spring Framework Predictable Session ID in WebSocket Module CWE-330 4.8 Medium 2026-06-09
CVE-2026-22745 CVE-2026-22745 : Denial of service in static resource handling on Windows platforms CWE-400 5.3 Medium 2026-04-29
CVE-2026-22741 Static resource cache poisoning in Spring MVC and WebFlux CWE-524 3.1 Low 2026-04-29
CVE-2026-22740 Spring Framework DoS with Multipart Temp Files in WebFlux CWE-400 6.5 Medium 2026-04-29
CVE-2026-22737 Spring Framework Improper Path Limitation with Script View Templates 5.9 Medium 2026-03-19
CVE-2025-41254 Spring Framework STOMP CSRF Vulnerability CWE-352 4.3 Medium 2025-10-16
CVE-2025-41249 CVE-2025-41249: Spring Framework Annotation Detection Vulnerability 7.5 High 2025-09-16
CVE-2025-41242 CVE-2025-41242: Path traversal vulnerability on non-compliant Servlet containers 5.9 Medium 2025-08-18
CVE-2025-41234 RFD Attack via “Content-Disposition” Header Sourced from Request CWE-113 6.5 Medium 2025-06-12
CVE-2025-22233 Spring Framework DataBinder Case Sensitive Match Exception CWE-20 3.1 Low 2025-05-16
CVE-2024-38819 VMware Spring Framework 安全漏洞 CWE-22 7.5 High 2024-12-19
CVE-2024-38809 VMware Spring Framework 安全漏洞 5.3 Medium 2024-09-27
CVE-2024-38808 CVE-2024-38808: Spring Expression DoS Vulnerability 4.3 Medium 2024-08-20
CVE-2024-22262 CVE-2024-22262: Spring Framework URL Parsing with Host Validation 8.1 High 2024-04-16
CVE-2024-22259 CVE-2024-22259: Spring Framework URL Parsing with Host Validation (2nd report) 8.1 High 2024-03-16
CVE-2024-22243 CVE-2024-22243: Spring Framework URL Parsing with Host Validation 8.1 High 2024-02-23
CVE-2024-22233 CVE-2024-22233: Spring Framework server Web DoS Vulnerability 7.5 High 2024-01-22
CVE-2023-34053 Spring Framework server Web Observations DoS Vulnerability 5.3 Medium 2023-11-28
CVE-2023-20863 Spring Framework 安全漏洞 CWE-400 6.5 - 2023-04-13
CVE-2023-20860 Spring Framework 安全漏洞 7.5 - 2023-03-27
CVE-2023-20861 Spring Framework 安全漏洞 6.5 - 2023-03-23
CVE-2022-22971 Spring Framework 输入验证错误漏洞 CWE-770 6.5 - 2022-05-12
CVE-2022-22970 Spring Framework 输入验证错误漏洞 CWE-770 6.5 - 2022-05-12
CVE-2022-22968 Vmware Spring Framework 安全特征问题漏洞 4.3 - 2022-04-14
CVE-2022-22950 Vmware Spring Framework 安全漏洞 CWE-770 6.5 - 2022-04-01
CVE-2022-22965 Spring Framework 代码注入漏洞 CWE-94 9.8 - 2022-04-01

All 78 known CVE vulnerabilities affecting Spring Framework with full Chinese analysis, references, and POCs where available.