38 Total CVEs
38 AI Analyzed
0 CISA KEV
10 Critical

Profile

0% ended up actively exploited 0 of 38 added to CISA KEV
26% rated critical (CVSS 9.0+) 10 critical, 28 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

37 CVEs in the last 12 months

Products

  • Spring Framework11
  • Spring AI7
  • Spring Security3
  • Spring Web Services3
  • Spring Boot3
  • Spring Tools for Eclipse2
  • Spring for GraphQL2
  • Spring Integration1

14 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-38 of 38 CVEs
CVE-2026-59324
Analyzed
8.2
Spring Spring Integration

When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same Fl...

2026-08-28
Full analysis →
CVE-2026-59316
Analyzed
8.2
Spring Spring Authorization Server

Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an...

2026-08-28
Full analysis →
CVE-2026-59313
Analyzed
9.8
Spring Spring Framework

Spring MVC applications using the functional web framework are vulnerable to stream corruption via CRLF injection when utilizing Server-Sent Events (S...

2026-09-01
Full analysis →
CVE-2026-59283
Analyzed
9.1
Spring Spring Framework

A safety guard bypass vulnerability in Spring Framework allows unauthenticated attackers to manipulate SpEL expressions when the compiler is active, p...

2026-09-01
Full analysis →
CVE-2026-59282
Analyzed
7.5
Spring Spring Framework

Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerab...

2026-09-02
Full analysis →
CVE-2026-59279
Analyzed
7.5
Spring Spring AI

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default d...

2026-08-23
Full analysis →
CVE-2026-47893
Analyzed
7.5
Spring Spring Framework

A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an e...

2026-09-03
Full analysis →
CVE-2026-47892
Analyzed
9.8
Spring Spring Framework

Spring Framework is susceptible to a header predicate bypass in pre-flight requests when using WebFlux functional endpoints with DispatcherServlet, po...

2026-09-01
Full analysis →
CVE-2026-47891
Analyzed
9.8
Spring Spring Framework

The Spring WebFlux component fails to enforce memory limits when using the Aalto XML processor, allowing for potential resource exhaustion.

2026-08-28
Full analysis →
CVE-2026-47890
Analyzed
9.8
Spring Spring Framework

Spring MVC and WebFlux applications are susceptible to stream corruption via CRLF injection when utilizing Server-Sent Events with view fragments.

2026-08-28
Full analysis →
CVE-2026-47889
Analyzed
7.5
Spring Spring Framework

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0...

2026-09-03
Full analysis →
CVE-2026-47886
Analyzed
7.5
Spring Spring Framework

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the...

2026-09-01
Full analysis →
CVE-2026-47884
Analyzed
9.8
Spring Spring Framework

An unauthenticated SSRF and RCE vulnerability exists in Spring MVC applications using XsltView with specific wildcard view rendering configurations.

2026-08-28
Full analysis →
CVE-2026-47882
Analyzed
8.3
Spring Spring Tools for Eclipse

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools...

2026-07-30
Full analysis →
CVE-2026-47877
Analyzed
8.2
Spring Spring Security

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring...

2026-08-28
Full analysis →
CVE-2026-47873
Analyzed
8
Spring Spring Tools for Eclipse

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0

2026-07-30
Full analysis →
CVE-2026-47835
Analyzed
8.6
Spring Spring AI

In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire Vec...

2026-06-16
Full analysis →
CVE-2026-47825
Analyzed
8.6
Spring Spring Cloud Gateway

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios

2026-06-16
Full analysis →
CVE-2026-41862
Analyzed
8.8
Spring Spring Statemachine

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforci...

2026-06-24
Full analysis →
CVE-2026-41705
Analyzed
8.6
Spring Spring AI

Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs

2026-05-09
Full analysis →
CVE-2026-41700
Analyzed
8.1
Spring Spring for GraphQL

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking

2026-06-14
Full analysis →
CVE-2026-41699
Analyzed
8.1
Spring Spring for GraphQL

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries

2026-06-14
Full analysis →
CVE-2026-40999
Analyzed
8.6
Spring Spring Web Services

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceM...

2026-06-11
Full analysis →
CVE-2026-40998
Analyzed
8.2
Spring Spring Web Services

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the J...

2026-06-12
Full analysis →
CVE-2026-40994
Analyzed
8.2
Spring Spring Web Services

Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement o...

2026-06-12
Full analysis →
CVE-2026-40982
Analyzed
9.1
Spring Spring Cloud Config

Spring Cloud Config allows directory traversal via specially crafted URLs, enabling unauthorized access to arbitrary files.

2026-05-07
Full analysis →
CVE-2026-40978
Analyzed
8.8
Spring Spring AI

SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs

2026-04-29
Full analysis →
CVE-2026-40976
Analyzed
9.1
Spring Spring Boot

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vu...

2026-04-28
Full analysis →
CVE-2026-40972
Analyzed
7.5
Spring Spring Boot

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret

2026-04-28
Full analysis →
CVE-2026-40967
Analyzed
8.6
Spring Spring AI

In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query la...

2026-04-28
Full analysis →
CVE-2026-22742
Analyzed
8.6
Spring Spring AI

Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal...

2026-03-27
Full analysis →
CVE-2026-22739
Analyzed
8.6
Spring Spring Cloud

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native f...

2026-03-24
Full analysis →
CVE-2026-22738
Analyzed
9.8
Spring Spring AI

Spring AI versions prior to 1.0.5 and 1.1.4 are vulnerable to SpEL injection in SimpleVectorStore when user-supplied input is used as a filter express...

2026-03-27
Full analysis →
CVE-2026-22733
Analyzed
8.2
Spring Spring Security

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authen...

2026-03-20
Full analysis →
CVE-2026-22731
Analyzed
8.2
Spring Spring Boot

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authen...

2026-03-20
Full analysis →
CVE-2025-41243
Analyzed
10
Spring Cloud Gateway

Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable whe...

2025-09-16
Full analysis →