Vmware Spring Framework vulnerabilities
87 known vulnerabilities affecting vmware/spring_framework.
Total CVEs
87
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH27MEDIUM45LOW3
Vulnerabilities
Page 3 of 5
CVE-2026-41842P3HIGHCVSS 7.5≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41842 [HIGH] CWE-400 CVE-2026-41842: Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-59282P3HIGHCVSS 7.5fixed in 5.2.26≥ 5.3.0, < 5.3.50+4 more2026-08-27
CVE-2026-59282 [HIGH] CWE-400 CVE-2026-59282: Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied p
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spri
nvd
CVE-2026-47886P3HIGHCVSS 7.5fixed in 5.2.26≥ 5.3.0, < 5.3.50+4 more2026-08-27
CVE-2026-47886 [HIGH] CWE-400 CVE-2026-47886: Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulner
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framew
nvd
CVE-2016-5007P3HIGHCVSS 7.5v3.2.1v3.2.2+43 more2017-05-25
CVE-2016-5007 [HIGH] CWE-264 CVE-2016-5007: Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching mechanisms, for example with regards to space trimming in path segments, can lead Spring Security to not re
nvd
CVE-2024-22233P3HIGHCVSS 7.5v6.0.15v6.1.22024-01-22
CVE-2024-22233 [HIGH] CWE-400 CVE-2024-22233: In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafte
In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Specifically, an application is vulnerable when all of the following are true:
* the application uses Spring MVC
* Spring Security 6.1.6+ or 6.2.1+ is on the classpath
Typically, Sp
nvd
CVE-2026-47885P3HIGHCVSS 7.5≥ 6.1.0, < 6.1.29≥ 6.2.0, < 6.2.20+1 more2026-08-27
CVE-2026-47885 [HIGH] CWE-770 CVE-2026-47885: The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMe
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
nvd
CVE-2013-7315P3MEDIUMCVSS 6.8≤ 3.2.3v3.0.6+10 more2014-01-23
CVE-2013-7315 [MEDIUM] CVE-2013-7315: The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable exter
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerab
nvd
CVE-2026-47888P3HIGHCVSS 7.5≥ 5.2.0, < 5.2.26≥ 5.3.0, < 5.3.50+4 more2026-08-27
CVE-2026-47888 [HIGH] CWE-401 CVE-2026-47888: A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framewo
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE
nvd
CVE-2026-22740P3MEDIUMCVSS 6.5fixed in 5.3.48≥ 6.1.0, < 6.1.27+3 more2026-04-29
CVE-2026-22740 [MEDIUM] CWE-400 CVE-2026-22740: A WebFlux server application that processes multipart requests creates temp files for parts larger t
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space.
Older, unsupported versions are also affected.
nvd
CVE-2014-3625P3MEDIUMCVSS 5.0≥ 3.0.4, ≤ 3.0.72014-11-20
CVE-2014-3625 [MEDIUM] CWE-22 CVE-2014-3625: Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
nvd
CVE-2018-1257P3MEDIUMCVSS 6.5fixed in 4.3.17≥ 5.0.0, < 5.0.62018-05-11
CVE-2018-1257 [MEDIUM] CVE-2018-1257: Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupport
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of
nvd
CVE-2025-41234P3MEDIUMCVSS 6.5≥ 6.0.5, ≤ 6.0.28≥ 6.1.0, ≤ 6.1.20+1 more2025-06-12
CVE-2025-41234 [MEDIUM] CWE-113 CVE-2025-41234: Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an applicati
Description
In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input.
Specifically, an application is vulnerable when all the
nvd
CVE-2026-41854P3MEDIUMCVSS 6.5≥ 6.2.0, < 6.2.18.1≥ 7.0.0, < 7.0.7.12026-06-09
CVE-2026-41854 [MEDIUM] CWE-918 CVE-2026-41854: Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
nvd
CVE-2022-22971P4MEDIUMCVSS 6.5≥ 5.2.0, ≤ 5.2.21≥ 5.3.0, ≤ 5.3.19+1 more2022-05-12
CVE-2022-22971 [MEDIUM] CWE-770 CVE-2022-22971: In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application wi
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
nvd
CVE-2026-22737P4MEDIUMCVSS 5.9fixed in 5.3.47≥ 6.1.0, < 6.1.26+2 more2026-03-20
CVE-2026-22737 [MEDIUM] CWE-22 CVE-2026-22737: Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring We
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.
nvd
CVE-2026-41843P4MEDIUMCVSS 5.9≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41843 [MEDIUM] CWE-22 CVE-2026-41843: Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static r
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2022-22968P4MEDIUMCVSS 5.3fixed in 5.2.0≥ 5.2.0, ≤ 5.2.20+1 more2022-04-14
CVE-2022-22968 [MEDIUM] CWE-178 CVE-2022-22968: In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the pat
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first charac
nvd
CVE-2018-11039P4MEDIUMCVSS 5.9fixed in 4.3.18≥ 5.0.0, < 5.0.72018-06-25
CVE-2018-11039 [MEDIUM] CVE-2018-11039: Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupport
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filt
nvd
CVE-2026-41841P4MEDIUMCVSS 5.9≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41841 [MEDIUM] CWE-524 CVE-2026-41841: Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41852P4MEDIUMCVSS 5.3≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41852 [MEDIUM] CWE-863 CVE-2026-41852: A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argu
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 throu
nvd