spring
OSS Librariesoss-project
Latest CVEs
The 15 most recently published vulnerabilities affecting spring.
- CVE-2026-59326HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server3.3
- CVE-2026-59328Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips4.2
- CVE-2026-59327Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations4.4
- CVE-2026-47882Spring Boot DevTools remote secret generated with a non-cryptographic PRNG8.3
- CVE-2026-47873Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces8.0
- CVE-2026-47858live information startup mode is vulnerable for remote code execution8.0
- CVE-2026-41862Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation ...8.8
- CVE-2026-47825Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situations8.6
- CVE-2026-41708Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability7.5
- CVE-2026-47835Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores8.6
- CVE-2026-41856Spring GraphQL Annotation Detection Vulnerability7.5
- CVE-2026-41700Cross-Site WebSocket Hijacking in Spring for GraphQL8.1
- CVE-2026-41699Unsafe Deserialization in Spring GraphQL8.1
- CVE-2026-41001Predictable Temp Directory in Artemis Auto-configuration5.3
- CVE-2026-41000WSS4J validation does not use configured replay cache3.7