Vmware Spring Framework vulnerabilities
87 known vulnerabilities affecting vmware/spring_framework.
Total CVEs
87
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH27MEDIUM45LOW3
Vulnerabilities
Page 1 of 5
CVE-2022-22965P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in 5.2.20≥ 5.3.0, < 5.3.182022-04-01
CVE-2022-22965 [CRITICAL] CWE-94 CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execut
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature
nvd
CVE-2018-1270P2CRITICALCVSS 9.8fixed in 4.3.16≥ 5.0.0, < 5.0.52018-04-06
CVE-2018-1270 [CRITICAL] CWE-94 CVE-2018-1270: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution
nvd
CVE-2018-1275P2CRITICALCVSS 9.8≥ 4.3.0, < 4.3.16≥ 5.0.0, < 5.0.52018-04-11
CVE-2018-1275 [CRITICAL] CVE-2018-1275: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
nvd
CVE-2018-1271P3MEDIUMCVSS 5.9PoC≥ 4.3.0, < 4.3.15≥ 5.0.0, < 5.0.52018-04-06
CVE-2018-1271 [MEDIUM] CWE-22 CVE-2018-1271: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a reque
nvd
CVE-2020-5398P2HIGHCVSS 7.5≥ 5.0.0, < 5.0.16≥ 5.1.0, < 5.1.13+1 more2020-01-17
CVE-2020-5398 [HIGH] CWE-79 CVE-2020-5398: In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
nvd
CVE-2016-1000027P2CRITICALCVSS 9.8fixed in 6.0.02020-01-02
CVE-2016-1000027 [CRITICAL] CWE-502 CVE-2016-1000027: Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue i
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intend
nvd
CVE-2013-6429P3MEDIUMCVSS 6.8v4.0.02014-01-26
CVE-2013-6429 [MEDIUM] CVE-2013-6429: The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013
nvd
CVE-2014-0054P3MEDIUMCVSS 6.8≤ 3.2.7v3.0.6+12 more2014-04-17
CVE-2014-0054 [MEDIUM] CVE-2014-0054: The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 be
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because o
nvd
CVE-2025-41242P3MEDIUMCVSS 5.9PoC≥ 6.2.x, < 6.2.10≥ 6.1.x, < 6.1.22+1 more2025-08-18
CVE-2025-41242 [MEDIUM] CWE-22 CVE-2025-41242: Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deploye
Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container.
An application can be vulnerable when all the following are true:
* the application is deployed as a WAR or with an embedded Servlet container
* the Servlet container does not reject suspicious sequences https:
nvd
CVE-2026-41855P3CRITICALCVSS 9.8≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41855 [CRITICAL] CWE-502 CVE-2026-41855: In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageCon
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization.
Affected versions:
Spring Framework 7.0.0 through 7.0.7;
nvd
CVE-2026-47892P3CRITICALCVSS 9.8≥ 5.2.5, < 5.2.26≥ 5.3.0, < 5.3.50+4 more2026-08-27
CVE-2026-47892 [CRITICAL] CWE-863 CVE-2026-47892: A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerab
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.5.RELEASE -
nvd
CVE-2026-59313P3CRITICALCVSS 9.8≥ 5.3.0, ≤ 5.3.49≥ 6.0.0, ≤ 6.0.30+3 more2026-08-27
CVE-2026-59313 [CRITICAL] CWE-93 CVE-2026-59313: Spring MVC applications using the functional web framework are vulnerable to stream corruption when
Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE).
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
nvd
CVE-2026-47890P3CRITICALCVSS 9.8≥ 6.2.0, < 6.2.20≥ 7.0.0, < 7.0.8.12026-08-27
CVE-2026-47890 [CRITICAL] CWE-93 CVE-2026-47890: Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Event
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
nvd
CVE-2018-1258P3HIGHCVSS 8.8v5.0.52018-05-11
CVE-2018-1258 [HIGH] CWE-863 CVE-2018-1258: Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contain
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
nvd
CVE-2013-4152P3MEDIUMCVSS 6.8≤ 3.2.3v3.0.6+10 more2014-01-23
CVE-2013-4152 [MEDIUM] CWE-264 CVE-2013-4152: The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource
nvd
CVE-2026-47884P3CRITICALCVSS 9.8fixed in 5.2.26≥ 5.3.0, < 5.3.50+4 more2026-08-27
CVE-2026-47884 [CRITICAL] CWE-22 CVE-2026-47884: Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3
nvd
CVE-2026-59283P3CRITICALCVSS 9.1fixed in 5.2.26≥ 5.3.0, < 5.3.50+4 more2026-08-27
CVE-2026-59283 [CRITICAL] CWE-913 CVE-2026-59283: Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationConte
Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
nvd
CVE-2018-15756P3HIGHCVSS 7.5≥ 4.2.0, < 4.3.20≥ 5.0.0, < 5.0.10+1 more2018-10-18
CVE-2018-15756 [HIGH] CVE-2018-15756: Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and o
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious u
nvd
CVE-2026-47891P3CRITICALCVSS 9.8fixed in 5.2.26≥ 5.3.0, < 5.3.50+4 more2026-08-27
CVE-2026-47891 [CRITICAL] CWE-770 CVE-2026-47891: A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not corr
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
nvd
CVE-2018-1272P3HIGHCVSS 7.5≥ 4.3.0, < 4.3.15≥ 5.0, < 5.0.52018-04-06
CVE-2018-1272 [HIGH] CVE-2018-1272: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be expose
nvd
1 / 5Next →