Vmware Spring Framework vulnerabilities
70 known vulnerabilities affecting vmware/spring_framework.
Total CVEs
70
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH21MEDIUM41LOW2
Vulnerabilities
Page 2 of 4
CVE-2025-41248P3HIGHCVSS 7.5≥ 6.2.x, < 6.2.11≥ 6.1.x, < 6.1.23+1 more2025-09-16
CVE-2025-41248 [HIGH] CWE-289 CVE-2025-41248: The Spring Security annotation detection mechanism may not correctly resolve annotations on methods
The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass.
Your application may be affected by this if you a
nvd
CVE-2016-9878P3HIGHCVSS 7.5v3.2.1v3.2.2+27 more2016-12-29
CVE-2016-9878 [HIGH] CWE-22 CVE-2016-9878: An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x bef
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
nvd
CVE-2024-22259P3HIGHCVSS 8.1fixed in 5.3.33≥ 6.0.0, < 6.0.18+1 more2024-03-16
CVE-2024-22259 [HIGH] CVE-2024-22259: Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
This
nvd
CVE-2021-22118P3HIGHCVSS 7.8≥ 5.2.0, < 5.2.15≥ 5.3.0, < 5.3.7+1 more2021-05-27
CVE-2021-22118 [HIGH] CWE-269 CVE-2021-22118: In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux app
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with mult
nvd
CVE-2020-5421P3MEDIUMCVSS 6.5fixed in 4.3.29≥ 5.0.0, < 5.0.19+2 more2020-09-19
CVE-2020-5421 [MEDIUM] CVE-2020-5421: In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and olde
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
nvd
CVE-2026-41851P3HIGHCVSS 7.5≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41851 [HIGH] CWE-770 CVE-2026-41851: Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnera
Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41850P3HIGHCVSS 7.5≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41850 [HIGH] CWE-407 CVE-2026-41850: Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerabl
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.
Affected versions:
Spring Framewor
nvd
CVE-2026-41848P3HIGHCVSS 7.5≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41848 [HIGH] CWE-1333 CVE-2026-41848: Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attack
Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, St
nvd
CVE-2026-41849P3HIGHCVSS 7.5≥ 5.3.0, < 5.3.492026-06-09
CVE-2026-41849 [HIGH] CWE-190 CVE-2026-41849: An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS).
Affected versions:
Spring Framework 5.3.0 through 5.3.48.
nvd
CVE-2014-0225P3HIGHCVSS 8.8v3.0.1v3.0.2+24 more2017-05-25
CVE-2014-0225 [HIGH] CWE-611 CVE-2014-0225: When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, an
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
nvd
CVE-2023-34053P3HIGHCVSS 7.5≥ 6.0.0, < 6.0.142023-11-28
CVE-2023-34053 [HIGH] CVE-2023-34053: In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted
In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Specifically, an application is vulnerable when all of the following are true:
* the application uses Spring MVC or Spring WebFlux
* io.micrometer:micrometer-core is on the classpath
* an Observ
nvd
CVE-2024-22233P3HIGHCVSS 7.5v6.0.15v6.1.22024-01-22
CVE-2024-22233 [HIGH] CWE-400 CVE-2024-22233: In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafte
In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Specifically, an application is vulnerable when all of the following are true:
* the application uses Spring MVC
* Spring Security 6.1.6+ or 6.2.1+ is on the classpath
Typically, Sp
nvd
CVE-2018-15801P3HIGHCVSS 7.4≥ 5.1.0, < 5.1.22018-12-19
CVE-2018-15801 [HIGH] CWE-345 CVE-2018-15801: Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during J
Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for
nvd
CVE-2026-41842P3HIGHCVSS 7.5≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41842 [HIGH] CWE-400 CVE-2026-41842: Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2016-5007P3HIGHCVSS 7.5v3.2.1v3.2.2+43 more2017-05-25
CVE-2016-5007 [HIGH] CWE-264 CVE-2016-5007: Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching mechanisms, for example with regards to space trimming in path segments, can lead Spring Security to not re
nvd
CVE-2013-7315P3MEDIUMCVSS 6.8≤ 3.2.3v3.0.6+10 more2014-01-23
CVE-2013-7315 [MEDIUM] CVE-2013-7315: The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable exter
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerab
nvd
CVE-2026-22740P3MEDIUMCVSS 6.5fixed in 5.3.48≥ 6.1.0, < 6.1.27+3 more2026-04-29
CVE-2026-22740 [MEDIUM] CWE-400 CVE-2026-22740: A WebFlux server application that processes multipart requests creates temp files for parts larger t
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space.
Older, unsupported versions are also affected.
nvd
CVE-2014-3625P3MEDIUMCVSS 5.0≥ 3.0.4, ≤ 3.0.72014-11-20
CVE-2014-3625 [MEDIUM] CWE-22 CVE-2014-3625: Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
nvd
CVE-2018-1257P3MEDIUMCVSS 6.5fixed in 4.3.17≥ 5.0.0, < 5.0.62018-05-11
CVE-2018-1257 [MEDIUM] CVE-2018-1257: Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupport
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of
nvd
CVE-2025-41234P3MEDIUMCVSS 6.5≥ 6.0.5, ≤ 6.0.28≥ 6.1.0, ≤ 6.1.20+1 more2025-06-12
CVE-2025-41234 [MEDIUM] CWE-113 CVE-2025-41234: Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an applicati
Description
In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input.
Specifically, an application is vulnerable when all the
nvd