When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same Fl...
Spring CVEs
38 high and critical vulnerabilities covered by CVE Brief since 2025-09-16, each with independent analyst commentary.
← All vendors RSS feed Watch this vendorProfile
Last 12 months
37 CVEs in the last 12 months
Products
- Spring Framework11
- Spring AI7
- Spring Security3
- Spring Web Services3
- Spring Boot3
- Spring Tools for Eclipse2
- Spring for GraphQL2
- Spring Integration1
14 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an...
Spring MVC applications using the functional web framework are vulnerable to stream corruption via CRLF injection when utilizing Server-Sent Events (S...
A safety guard bypass vulnerability in Spring Framework allows unauthenticated attackers to manipulate SpEL expressions when the compiler is active, p...
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerab...
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default d...
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an e...
Spring Framework is susceptible to a header predicate bypass in pre-flight requests when using WebFlux functional endpoints with DispatcherServlet, po...
The Spring WebFlux component fails to enforce memory limits when using the Aalto XML processor, allowing for potential resource exhaustion.
Spring MVC and WebFlux applications are susceptible to stream corruption via CRLF injection when utilizing Server-Sent Events with view fragments.
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0...
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the...
An unauthenticated SSRF and RCE vulnerability exists in Spring MVC applications using XsltView with specific wildcard view rendering configurations.
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools...
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring...
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire Vec...
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforci...
In an untrusted JMS environment, org
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries
When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceM...
Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the J...
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement o...
Spring Cloud Config allows directory traversal via specially crafted URLs, enabling unauthorized access to arbitrary files.
SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vu...
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret
In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query la...
Vulnerability in Spring Spring Security
Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal...
Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native f...
Spring AI versions prior to 1.0.5 and 1.1.4 are vulnerable to SpEL injection in SimpleVectorStore when user-supplied input is used as a filter express...
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authen...
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authen...
Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable whe...