cbcvebase.

Spring Framework vulnerabilities

43 known vulnerabilities affecting spring/spring_framework.

Total CVEs
43
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH16MEDIUM19LOW1

Vulnerabilities

Page 2 of 3
CVE-2024-22233P3HIGHCVSS 7.5v6.1.2v6.0.152024-01-22
CVE-2024-22233 [HIGH] CWE-400 CVE-2024-22233: In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafte In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC * Spring Security 6.1.6+ or 6.2.1+ is on the classpath Typically, Sp
nvd
CVE-2026-47885P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+1 more2026-08-27
CVE-2026-47885 [HIGH] CWE-770 CVE-2026-47885: The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMe The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28
nvd
CVE-2026-47888P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-47888 [HIGH] CWE-401 CVE-2026-47888: A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framewo A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE
nvd
CVE-2026-41854P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.12026-06-09
CVE-2026-41854 [MEDIUM] CWE-918 CVE-2026-41854: Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
nvd
CVE-2026-22737P4MEDIUMCVSS 5.9≥ 7.0.0, ≤ 7.0.5≥ 6.2.0, ≤ 6.2.16+2 more2026-03-20
CVE-2026-22737 [MEDIUM] CWE-22 CVE-2026-22737: Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring We Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.
nvd
CVE-2026-41843P4MEDIUMCVSS 5.9≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41843 [MEDIUM] CWE-22 CVE-2026-41843: Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static r Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41841P4MEDIUMCVSS 5.9≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41841 [MEDIUM] CWE-524 CVE-2026-41841: Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41852P4MEDIUMCVSS 5.3≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41852 [MEDIUM] CWE-863 CVE-2026-41852: A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argu A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 throu
nvd
CVE-2020-5397P4MEDIUMCVSS 5.3≥ 5.2, < v5.2.3.RELEASE2020-01-17
CVE-2020-5397 [MEDIUM] CWE-352 CVE-2020-5397: Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS prefligh Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail au
nvd
CVE-2026-41844P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41844 [MEDIUM] CWE-601 CVE-2026-41844: A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3
nvd
CVE-2026-41840P4MEDIUMCVSS 5.9≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41840 [MEDIUM] CWE-400 CVE-2026-41840: Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multip Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
nvd
CVE-2026-41853P4MEDIUMCVSS 5.3≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41853 [MEDIUM] CWE-444 CVE-2026-41853: Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41847P4MEDIUMCVSS 5.3≥ 5.3.0, < 5.3.492026-06-09
CVE-2026-41847 [MEDIUM] CWE-284 CVE-2026-41847: Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.
nvd
CVE-2026-59281P4MEDIUMCVSS 6.1≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-59281 [MEDIUM] CWE-79 CVE-2026-59281: Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping en Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors are vulnerable to arbitrary HTML/JavaScript code injection, potentially resulting in a reflected cross-site scripting (XSS) vulnerabili
nvd
CVE-2026-47887P4MEDIUMCVSS 6.1≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-47887 [MEDIUM] CWE-601 CVE-2026-47887: A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.2
nvd
CVE-2026-41846P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41846 [MEDIUM] CWE-79 CVE-2026-41846: Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyl Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3
nvd
CVE-2026-41845P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41845 [MEDIUM] CWE-79 CVE-2026-41845: Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-47883P4MEDIUMCVSS 6.1≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.192026-08-27
CVE-2026-47883 [MEDIUM] CWE-601 CVE-2026-47883: UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching pa UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
nvd
CVE-2024-38820P4MEDIUMCVSS 5.3≥ 6.2.0, ≤ 6.2.6≥ 6.1.0, ≤ 6.1.19+2 more2024-10-18
CVE-2024-38820 [MEDIUM] CWE-178 CVE-2024-38820: The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, S The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
nvd
CVE-2026-59280P4MEDIUMCVSS 4.3≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-59280 [MEDIUM] CWE-22 CVE-2026-59280: Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal a Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spri
nvd
Spring Framework vulnerabilities | cvebase