Spring Framework vulnerabilities
26 known vulnerabilities affecting spring/spring_framework.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM15
Vulnerabilities
Page 2 of 2
CVE-2026-41847P4MEDIUMCVSS 5.3≥ 5.3.0, < 5.3.492026-06-09
CVE-2026-41847 [MEDIUM] CWE-284 CVE-2026-41847: Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Affected versions:
Spring Framework 5.3.0 through 5.3.48.
nvd
CVE-2026-41846P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41846 [MEDIUM] CWE-79 CVE-2026-41846: Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyl
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3
nvd
CVE-2026-41845P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41845 [MEDIUM] CWE-79 CVE-2026-41845: Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code
Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2024-38820P4MEDIUMCVSS 5.3≥ 6.2.0, ≤ 6.2.6≥ 6.1.0, ≤ 6.1.19+2 more2024-10-18
CVE-2024-38820 [MEDIUM] CWE-178 CVE-2024-38820: The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, S
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
nvd
CVE-2026-41839P4MEDIUMCVSS 4.2≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41839 [MEDIUM] CWE-384 CVE-2026-41839: A WebFlux application with a compromised subdomain (for example, compromised via cross-site scriptin
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2024-38808P4MEDIUMCVSS 4.3≥ 5.3.0, < 5.3.39, 6.0+2024-08-20
CVE-2024-38808 [MEDIUM] CWE-770 CVE-2024-38808: In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a use
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.
Specifically, an application is vulnerable when the following is true:
* The application evaluates user-supplied SpEL e
nvd
← Previous2 / 2