← Back to feed Search feed

Spring Framework vulnerabilities

11 entries matching spring — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-68494The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypHIGH8.7NVD2026-08-04
CVE-2026-18401The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in SMEDIUM6.9NVD2026-08-04
CVE-2026-41695Spring Data: Unbounded property-path cache keyed by externally-supplied path stringHIGH7.529%ileGitHub2026-07-31
CVE-2026-47882When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud FounHIGH8.37%ileNVD2026-07-30
CVE-2026-47858Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applicatiHIGH8.010%ileNVD2026-07-30
CVE-2026-47873The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network intHIGH8.08%ileNVD2026-07-30
CVE-2026-59327Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain stringMEDIUM4.40%ileNVD2026-07-30
CVE-2026-59328Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT BrowseMEDIUM4.26%ileNVD2026-07-30
CVE-2026-59326The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variLOW3.31%ileNVD2026-07-30
CVE-2026-8338A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.CRITICAL9.222%ileNVD2026-07-29
CVE-2026-50338Azure Spring Apps Elevation of Privilege VulnerabilityHIGH8.238%ileMicrosoft2026-07-14