cbcvebase.

Spring Framework vulnerabilities

43 known vulnerabilities affecting spring/spring_framework.

Total CVEs
43
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH16MEDIUM19LOW1

Vulnerabilities

Page 1 of 3
CVE-2020-5398P2HIGHCVSS 7.5≥ 5.0, < v5.0.16.RELEASE≥ 5.1, < v5.1.13.RELEASE+1 more2020-01-17
CVE-2020-5398 [HIGH] CWE-79 CVE-2020-5398: In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0 In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
nvd
CVE-2026-41855P3CRITICALCVSS 9.8≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41855 [CRITICAL] CWE-502 CVE-2026-41855: In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageCon In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7;
nvd
CVE-2026-47892P3CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-47892 [CRITICAL] CWE-863 CVE-2026-47892: A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerab A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE -
nvd
CVE-2026-59313P3CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+3 more2026-08-27
CVE-2026-59313 [CRITICAL] CWE-93 CVE-2026-59313: Spring MVC applications using the functional web framework are vulnerable to stream corruption when Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49
nvd
CVE-2026-47890P3CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.192026-08-27
CVE-2026-47890 [CRITICAL] CWE-93 CVE-2026-47890: Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Event Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
nvd
CVE-2026-47884P3CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-47884 [CRITICAL] CWE-22 CVE-2026-47884: Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3
nvd
CVE-2026-59283P3CRITICALCVSS 9.1≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-59283 [CRITICAL] CWE-913 CVE-2026-59283: Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationConte Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49
nvd
CVE-2026-47891P3CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-47891 [CRITICAL] CWE-770 CVE-2026-47891: A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not corr A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
nvd
CVE-2026-41838P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41838 [HIGH] CWE-330 CVE-2026-41838: IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, w IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2024-22243P3HIGHCVSS 8.1≥ 6.1.x, < 6.1.6≥ 6.0.x, < 6.0.19+1 more2024-02-23
CVE-2024-22243 [HIGH] CWE-601 CVE-2024-22243: Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
nvd
CVE-2026-47893P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-47893 [HIGH] CWE-209 CVE-2026-47893: A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive use A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.REL
nvd
CVE-2026-41851P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41851 [HIGH] CWE-770 CVE-2026-41851: Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnera Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41850P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41850 [HIGH] CWE-407 CVE-2026-41850: Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerabl Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framewor
nvd
CVE-2026-41848P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41848 [HIGH] CWE-1333 CVE-2026-41848: Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attack Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, St
nvd
CVE-2026-41849P3HIGHCVSS 7.5≥ 5.3.0, < 5.3.492026-06-09
CVE-2026-41849 [HIGH] CWE-190 CVE-2026-41849: An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language ( An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.
nvd
CVE-2026-47889P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.192026-08-27
CVE-2026-47889 [HIGH] CWE-1275 CVE-2026-47889: A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies with A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
nvd
CVE-2023-34053P3HIGHCVSS 7.5≥ 6.0.0, < 6.0.142023-11-28
CVE-2023-34053 [HIGH] CVE-2023-34053: In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * io.micrometer:micrometer-core is on the classpath * an Observ
nvd
CVE-2026-41842P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41842 [HIGH] CWE-400 CVE-2026-41842: Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-59282P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-59282 [HIGH] CWE-400 CVE-2026-59282: Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied p Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spri
nvd
CVE-2026-47886P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-47886 [HIGH] CWE-400 CVE-2026-47886: Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulner Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framew
nvd
Spring Framework vulnerabilities | cvebase