Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Spring — Vulnerabilities & Security Advisories 247

Browse all 247 CVE security advisories affecting Spring. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Spring is a widely adopted Java framework designed for building enterprise-level applications, serving as the backbone for numerous critical web services. Its extensive ecosystem has historically exposed developers to diverse security risks, particularly Remote Code Execution (RCE) and Server-Side Request Forgery (SSRF), stemming from complex request handling and deserialization flaws. While Cross-Site Scripting (XSS) and privilege escalation issues also appear in the record, the most severe incidents involve critical RCE vulnerabilities that allow attackers to execute arbitrary code on affected servers. The framework’s modular nature means vulnerabilities in specific components, such as Spring Boot or Spring Security, can impact the entire application stack. With 72 recorded CVEs, maintaining strict dependency updates and adhering to secure coding practices are essential for mitigating these persistent threats in production environments.

CVE ID Title CVSS Severity Published
CVE-2026-59323 Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability — Micrometer Tracing 5.3 Medium 2026-08-21
CVE-2026-59326 HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server — Spring Tools for Eclipse 3.3 Low 2026-07-30
CVE-2026-59328 Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips — Spring Tools for Eclipse 4.2 Medium 2026-07-30
CVE-2026-59327 Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations — Spring Tools for Eclipse 4.4 Medium 2026-07-30
CVE-2026-47882 Spring Boot DevTools remote secret generated with a non-cryptographic PRNG — Spring Tools for Eclipse 8.3 High 2026-07-30
CVE-2026-47873 Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces — Spring Tools for Eclipse 8.0 High 2026-07-30
CVE-2026-47858 live information startup mode is vulnerable for remote code execution — Spring Tools for Eclipse 8.0 High 2026-07-30
CVE-2026-41862 Spring Statemachine 反序列化注入漏洞 — Spring Statemachine CWE-502 8.8 High 2026-06-23
CVE-2026-47825 Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situations — Spring Cloud Gateway CWE-346 8.6 High 2026-06-15
CVE-2026-41708 Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability — Spring Cloud Sleuth CWE-400 7.5 High 2026-06-15
CVE-2026-47835 Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores — Spring AI CWE-943 8.6 High 2026-06-15
CVE-2026-41856 Spring GraphQL Annotation Detection Vulnerability — Spring for GraphQL CWE-284 7.5 High 2026-06-11
CVE-2026-41700 Cross-Site WebSocket Hijacking in Spring for GraphQL — Spring for GraphQL CWE-346 8.1 High 2026-06-11
CVE-2026-41699 Unsafe Deserialization in Spring GraphQL — Spring for GraphQL CWE-502 8.1 High 2026-06-11
CVE-2026-41001 Predictable Temp Directory in Artemis Auto-configuration — Spring Boot CWE-377 5.3 Medium 2026-06-11
CVE-2026-41000 WSS4J validation does not use configured replay cache — Spring Web Services CWE-294 3.7 Low 2026-06-11
CVE-2026-40999 Spring WS SSRF via unvalidated WS-Addressing reply destinations — Spring Web Services CWE-918 8.6 High 2026-06-11
CVE-2026-40998 Jaxp13 XPath XXE via StreamSource and SAXSource — Spring Web Services CWE-611 8.2 High 2026-06-11
CVE-2026-40997 SOAP security faults leak Spring Security account state — Spring Web Services CWE-209 5.3 Medium 2026-06-11
CVE-2026-40996 Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default — Spring Web Services CWE-327 4.8 Medium 2026-06-11
CVE-2026-40995 X.509 authentication bypasses Spring Security account checks — Spring Web Services CWE-287 5.4 Medium 2026-06-11
CVE-2026-40994 Wss4jSecurityInterceptor disables WS-I BSP validation by default — Spring Web Services CWE-1188 8.2 High 2026-06-11
CVE-2026-40992 Mail Auto-Configuration Does Not Enable SSL Hostname Verification — Spring Boot CWE-295 5.0 Medium 2026-06-11
CVE-2026-40987 Remote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalization — Spring Integration CWE-22 7.1 High 2026-06-11
CVE-2026-40986 Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML — Spring Web Flow CWE-79 4.8 Medium 2026-06-11
CVE-2026-40985 Data Binding Vulnerability in Spring Web Flow with Unified EL Parser — Spring Web Flow CWE-917 6.4 Medium 2026-06-11
CVE-2026-47838 Unauthorized User Impersonation when Using X.509 Client Certificates — Spring Security CWE-287 6.8 Medium 2026-06-09
CVE-2026-41837 Spring Data REST Querydsl integration exposes Jackson-hidden persistent fields as filter keys — Spring Data REST CWE-284 5.3 Medium 2026-06-09
CVE-2026-41732 In Spring for Apache Pulsar, overly broad trusted-package matching in header mapper exposes JDK classes to deserialization — Spring for Apache Pulsar CWE-502 8.1 High 2026-06-09
CVE-2026-41731 In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization — Spring for Apache Kafka CWE-502 8.1 High 2026-06-09

This page lists every published CVE security advisory associated with Spring. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.