Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Spring — Vulnerabilities & Security Advisories 247

Browse all 247 CVE security advisories affecting Spring. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Spring is a widely adopted Java framework designed for building enterprise-level applications, serving as the backbone for numerous critical web services. Its extensive ecosystem has historically exposed developers to diverse security risks, particularly Remote Code Execution (RCE) and Server-Side Request Forgery (SSRF), stemming from complex request handling and deserialization flaws. While Cross-Site Scripting (XSS) and privilege escalation issues also appear in the record, the most severe incidents involve critical RCE vulnerabilities that allow attackers to execute arbitrary code on affected servers. The framework’s modular nature means vulnerabilities in specific components, such as Spring Boot or Spring Security, can impact the entire application stack. With 72 recorded CVEs, maintaining strict dependency updates and adhering to secure coding practices are essential for mitigating these persistent threats in production environments.

Found 16 results / 247 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-59324 fluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunction — Spring Integration 8.2 High 2026-08-27
CVE-2026-59322 EmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeaders — Spring Integration 6.3 Medium 2026-08-27
CVE-2026-59321 Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check — Spring Integration 4.2 Medium 2026-08-27
CVE-2026-59311 Fixed predictable /tmp/ziptransformer work directory enables symlink pre-creation — Spring Integration 6.8 Medium 2026-08-27
CVE-2026-59307 Deserialization allow-list silently bypassed: setBeanClassLoader replaces deserializer but mapper keeps stale reference — Spring Integration 8.0 High 2026-08-27
CVE-2026-59293 SMB minimum protocol dialect defaults to SMB1 — Spring Integration 6.6 Medium 2026-08-27
CVE-2026-59292 World-readable metadata file in PropertiesPersistingMetadataStore (insecure temp-file permissions) — Spring Integration 3.2 Low 2026-08-27
CVE-2026-59274 Unbounded decompression in UnZipTransformer enables zip-bomb DoS — Spring Integration 6.5 Medium 2026-08-27
CVE-2026-47880 DefaultJmsHeaderMapper copies all JMS user properties into MessageHeaders without excluding framework-significant names — Spring Integration 5.4 Medium 2026-08-27
CVE-2026-47864 Unsafe Java deserialization in SerializingHttpMessageConverter — remote code execution — Spring Integration 6.4 Medium 2026-08-27
CVE-2026-47861 UDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when acknowledge=false — Spring Integration 6.3 Medium 2026-08-26
CVE-2026-47862 ZipTransformer uses file_name header to build workDirectory path without sanitization — Spring Integration 5.4 Medium 2026-08-26
CVE-2026-47859 Unbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoS — Spring Integration 5.4 Medium 2026-08-26
CVE-2026-47856 JsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-list — Spring Integration 6.3 Medium 2026-08-26
CVE-2026-40987 Remote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalization — Spring Integration CWE-22 7.1 High 2026-06-11
CVE-2019-3772 Spring Integration XML External Entity Injection (XXE) — Spring Integration CWE-611 9.8 - 2019-01-18

This page lists every published CVE security advisory associated with Spring. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.