spring
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting spring.
- CVE-2026-59324fluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunction8.2
- CVE-2026-59322EmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeaders6.3
- CVE-2026-59321Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check4.2
- CVE-2026-59320In Spring AMQP the link credit never replenished on listener exception path6.5
- CVE-2026-59317In Spring for Apache Kafka, missing header validation in DeadLetterPublishingRecovererFactory enables denial of service via a poison-pill loop6.5
- CVE-2026-59319RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data Exposure4.3
- CVE-2026-59316Spring Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS)8.2
- CVE-2026-59315Spring Cloud Config Monitor Denial of Service5.3
- CVE-2026-59314Spring Framework response splitting in ContentDisposition3.7
- CVE-2026-59311Fixed predictable /tmp/ziptransformer work directory enables symlink pre-creation6.8
- CVE-2026-59306Potential for deserialization of untrusted types in Spring Cloud Stream3.1
- CVE-2026-59313Server Sent Event stream corruption in Spring MVC functional web framework9.8
- CVE-2026-59307Deserialization allow-list silently bypassed: setBeanClassLoader replaces deserializer but mapper keeps stale reference8.0
- CVE-2026-59305Partition interceptor may be improperly added while sending message3.1
- CVE-2026-59304Improper caching of the original content type in Spring Cloud Stream Avro3.1