Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Spring — Vulnerabilities & Security Advisories 247

Browse all 247 CVE security advisories affecting Spring. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Spring is a widely adopted Java framework designed for building enterprise-level applications, serving as the backbone for numerous critical web services. Its extensive ecosystem has historically exposed developers to diverse security risks, particularly Remote Code Execution (RCE) and Server-Side Request Forgery (SSRF), stemming from complex request handling and deserialization flaws. While Cross-Site Scripting (XSS) and privilege escalation issues also appear in the record, the most severe incidents involve critical RCE vulnerabilities that allow attackers to execute arbitrary code on affected servers. The framework’s modular nature means vulnerabilities in specific components, such as Spring Boot or Spring Security, can impact the entire application stack. With 72 recorded CVEs, maintaining strict dependency updates and adhering to secure coding practices are essential for mitigating these persistent threats in production environments.

CVE ID Title CVSS Severity Published
CVE-2026-59324 fluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunction — Spring Integration 8.2 High 2026-08-27
CVE-2026-59322 EmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeaders — Spring Integration 6.3 Medium 2026-08-27
CVE-2026-59321 Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check — Spring Integration 4.2 Medium 2026-08-27
CVE-2026-59320 In Spring AMQP the link credit never replenished on listener exception path — Spring AMQP 6.5 Medium 2026-08-27
CVE-2026-59319 RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data Exposure — Spring AI 4.3 Medium 2026-08-27
CVE-2026-59317 In Spring for Apache Kafka, missing header validation in DeadLetterPublishingRecovererFactory enables denial of service via a poison-pill loop — Spring for Apache Kafka 6.5 Medium 2026-08-27
CVE-2026-59316 Spring Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS) — Spring Authorization Server 8.2 High 2026-08-27
CVE-2026-59315 Spring Cloud Config Monitor Denial of Service — Spring Cloud Config 5.3 Medium 2026-08-27
CVE-2026-59314 Spring Framework response splitting in ContentDisposition — Spring Framework - - 2026-08-27
CVE-2026-59311 Fixed predictable /tmp/ziptransformer work directory enables symlink pre-creation — Spring Integration 6.8 Medium 2026-08-27
CVE-2026-59306 Potential for deserialization of untrusted types in Spring Cloud Stream — Spring Cloud Stream 3.1 Low 2026-08-27
CVE-2026-59313 Server Sent Event stream corruption in Spring MVC functional web framework — Spring Framework - - 2026-08-27
CVE-2026-59307 Deserialization allow-list silently bypassed: setBeanClassLoader replaces deserializer but mapper keeps stale reference — Spring Integration 8.0 High 2026-08-27
CVE-2026-59305 Partition interceptor may be improperly added while sending message — Spring Cloud Stream 3.1 Low 2026-08-27
CVE-2026-59304 Improper caching of the original content type in Spring Cloud Stream Avro — Spring Cloud Stream 3.1 Low 2026-08-27
CVE-2026-59303 Dynamic destination cache size is not properly bound in Spring Cloud Stream — Spring Cloud Stream 3.1 Low 2026-08-27
CVE-2026-59302 Potential for logging sensitive data in Spring Cloud Stream — Spring Cloud Stream 3.1 Low 2026-08-27
CVE-2026-59301 Potential for logging sensitive data in Spring Cloud Function Azure — Spring Cloud Function 3.1 Low 2026-08-27
CVE-2026-59300 Potential for logging sensitive data in Spring Cloud Function AWS — Spring Cloud Function 3.1 Low 2026-08-27
CVE-2026-59299 Composition lookup can potentially poison base function in Spring Cloud Function — Spring Cloud Function 3.1 Low 2026-08-27
CVE-2026-59298 Potential for improper filtering of HTTP headers in Spring Cloud Function — Spring Cloud Function 3.1 Low 2026-08-27
CVE-2026-59297 Spring Cloud Function can incorrectly determine if URI is secure — Spring Cloud Function 3.1 Low 2026-08-27
CVE-2026-59294 Arbitrary File Write via Path Traversal in ResourceCacheService — Spring AI 5.9 Medium 2026-08-27
CVE-2026-59293 SMB minimum protocol dialect defaults to SMB1 — Spring Integration 6.6 Medium 2026-08-27
CVE-2026-59292 World-readable metadata file in PropertiesPersistingMetadataStore (insecure temp-file permissions) — Spring Integration 3.2 Low 2026-08-27
CVE-2026-59291 Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function — Spring Cloud Function 2.0 Low 2026-08-27
CVE-2026-59289 Spring for GraphQL Denial of Service via pagination support — Spring for GraphQL - - 2026-08-27
CVE-2026-59288 Spring for GraphQL Information Exposure in GraphiQL support — Spring for GraphQL - - 2026-08-27
CVE-2026-59287 Spring for GraphQL WebSocket Client Denial of Service — Spring for GraphQL - - 2026-08-27
CVE-2026-59286 Spring for GraphQL loads Untrusted Resources in GraphiQL support — Spring for GraphQL - - 2026-08-27

This page lists every published CVE security advisory associated with Spring. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.