Spring Framework vulnerabilities
43 known vulnerabilities affecting spring/spring_framework.
Total CVEs
43
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH16MEDIUM19LOW1
Vulnerabilities
Page 3 of 3
CVE-2026-41839P4MEDIUMCVSS 4.2≥ 7.0.0, < 7.0.7.1≥ 6.2.0, < 6.2.18.1+2 more2026-06-09
CVE-2026-41839 [MEDIUM] CWE-384 CVE-2026-41839: A WebFlux application with a compromised subdomain (for example, compromised via cross-site scriptin
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2024-38808P4MEDIUMCVSS 4.3≥ 5.3.0, < 5.3.39, 6.0+2024-08-20
CVE-2024-38808 [MEDIUM] CWE-770 CVE-2024-38808: In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a use
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.
Specifically, an application is vulnerable when the following is true:
* The application evaluates user-supplied SpEL e
nvd
CVE-2026-59314P4LOWCVSS 3.7≥ 7.0.0, ≤ 7.0.8≥ 6.2.0, ≤ 6.2.19+4 more2026-08-27
CVE-2026-59314 [LOW] CWE-113 CVE-2026-59314: Applications that build a Content-Disposition header value from untrusted input may be vulnerable to
Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEA
nvd
← Previous3 / 3