Spring framework
This hub aggregates every CVE we track for Spring framework, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
102
CVEs tracked
13
Critical
32
High
2
In CISA KEV
Severity distribution
MEDIUM50HIGH32CRITICAL13LOW7
Monthly trend
2
0
1
0
1
0
0
1
1
0
1
1
1
0
0
0
0
2
3
0
18
0
17
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Spring framework.
- CVE-2026-59314Spring Framework response splitting in ContentDisposition3.7
- CVE-2026-59313Server Sent Event stream corruption in Spring MVC functional web framework9.8
- CVE-2026-59283Spring Framework Safety Guard Bypass via SpEL Expression Compilation9.1
- CVE-2026-59282Spring Framework Denial of Service via Unbounded List Growth in Data Binding7.5
- CVE-2026-59281Spring Framework Cross-site Scripting via EscapedErrors6.1
- CVE-2026-59280Spring Framework Path Traversal via Backslash in SpringTemplateLoader4.3
- CVE-2026-47893Spring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketService7.5
- CVE-2026-47892Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints9.8
- CVE-2026-47891Spring Framework maxInMemorySize Bypassed in Jaxb2Decoder9.8
- CVE-2026-47890Spring Framework Server Sent Event stream corruption while rendering fragments9.8
- CVE-2026-47889Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse7.5
- CVE-2026-47888Spring Framework Memory Leak via SETUP Frame in RSocketMessageHandler7.5
- CVE-2026-47887Spring Framework Open Redirect in UrlFileNameViewController6.1
- CVE-2026-47886Spring Framework Denial of Service via Unbounded Exponentiation in SpEL Expressions7.5
- CVE-2026-47885Spring Framework maxPartSize Ignored in PartEventHttpMessageReader7.5
Product normalization is registry-driven with AI assist and human review. How it works