cbcvebase.

Spring Framework vulnerabilities

26 known vulnerabilities affecting spring/spring_framework.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM15

Vulnerabilities

Page 1 of 2
CVE-2020-5398P2HIGHCVSS 7.5≥ 5.0, < v5.0.16.RELEASE≥ 5.1, < v5.1.13.RELEASE+1 more2020-01-17
CVE-2020-5398 [HIGH] CWE-79 CVE-2020-5398: In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0 In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
nvd
CVE-2026-41855P3CRITICALCVSS 9.8≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41855 [CRITICAL] CWE-502 CVE-2026-41855: In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageCon In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7;
nvd
CVE-2024-22243P3HIGHCVSS 8.1≥ 6.1.x, < 6.1.6≥ 6.0.x, < 6.0.19+1 more2024-02-23
CVE-2024-22243 [HIGH] CWE-601 CVE-2024-22243: Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
nvd
CVE-2026-41838P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41838 [HIGH] CWE-330 CVE-2026-41838: IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, w IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41851P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41851 [HIGH] CWE-770 CVE-2026-41851: Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnera Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41850P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41850 [HIGH] CWE-407 CVE-2026-41850: Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerabl Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framewor
nvd
CVE-2026-41848P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41848 [HIGH] CWE-1333 CVE-2026-41848: Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attack Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, St
nvd
CVE-2026-41849P3HIGHCVSS 7.5≥ 5.3.0, < 5.3.492026-06-09
CVE-2026-41849 [HIGH] CWE-190 CVE-2026-41849: An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language ( An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.
nvd
CVE-2023-34053P3HIGHCVSS 7.5≥ 6.0.0, < 6.0.142023-11-28
CVE-2023-34053 [HIGH] CVE-2023-34053: In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * io.micrometer:micrometer-core is on the classpath * an Observ
nvd
CVE-2024-22233P3HIGHCVSS 7.5v6.1.2v6.0.152024-01-22
CVE-2024-22233 [HIGH] CWE-400 CVE-2024-22233: In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafte In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC * Spring Security 6.1.6+ or 6.2.1+ is on the classpath Typically, Sp
nvd
CVE-2026-41842P3HIGHCVSS 7.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41842 [HIGH] CWE-400 CVE-2026-41842: Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41854P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.12026-06-09
CVE-2026-41854 [MEDIUM] CWE-918 CVE-2026-41854: Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
nvd
CVE-2026-22737P4MEDIUMCVSS 5.9≥ 7.0.0, ≤ 7.0.5≥ 6.2.0, ≤ 6.2.16+2 more2026-03-20
CVE-2026-22737 [MEDIUM] CWE-22 CVE-2026-22737: Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring We Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.
nvd
CVE-2026-41843P4MEDIUMCVSS 5.9≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41843 [MEDIUM] CWE-22 CVE-2026-41843: Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static r Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41841P4MEDIUMCVSS 5.9≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41841 [MEDIUM] CWE-524 CVE-2026-41841: Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41852P4MEDIUMCVSS 5.3≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41852 [MEDIUM] CWE-863 CVE-2026-41852: A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argu A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 throu
nvd
CVE-2020-5397P4MEDIUMCVSS 5.3≥ 5.2, < v5.2.3.RELEASE2020-01-17
CVE-2020-5397 [MEDIUM] CWE-352 CVE-2020-5397: Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS prefligh Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail au
nvd
CVE-2026-41844P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41844 [MEDIUM] CWE-601 CVE-2026-41844: A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3
nvd
CVE-2026-41840P4MEDIUMCVSS 5.9≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41840 [MEDIUM] CWE-400 CVE-2026-41840: Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multip Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
nvd
CVE-2026-41853P4MEDIUMCVSS 5.3≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41853 [MEDIUM] CWE-444 CVE-2026-41853: Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd