Vmware Spring Framework vulnerabilities
70 known vulnerabilities affecting vmware/spring_framework.
Total CVEs
70
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH21MEDIUM41LOW2
Vulnerabilities
Page 3 of 4
CVE-2026-41854P3MEDIUMCVSS 6.5≥ 6.2.0, < 6.2.18.1≥ 7.0.0, < 7.0.7.12026-06-09
CVE-2026-41854 [MEDIUM] CWE-918 CVE-2026-41854: Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
nvd
CVE-2022-22971P4MEDIUMCVSS 6.5≥ 5.2.0, ≤ 5.2.21≥ 5.3.0, ≤ 5.3.19+1 more2022-05-12
CVE-2022-22971 [MEDIUM] CWE-770 CVE-2022-22971: In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application wi
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
nvd
CVE-2026-22737P4MEDIUMCVSS 5.9fixed in 5.3.47≥ 6.1.0, < 6.1.26+2 more2026-03-20
CVE-2026-22737 [MEDIUM] CWE-22 CVE-2026-22737: Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring We
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.
nvd
CVE-2026-41843P4MEDIUMCVSS 5.9≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41843 [MEDIUM] CWE-22 CVE-2026-41843: Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static r
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2022-22968P4MEDIUMCVSS 5.3fixed in 5.2.0≥ 5.2.0, ≤ 5.2.20+1 more2022-04-14
CVE-2022-22968 [MEDIUM] CWE-178 CVE-2022-22968: In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the pat
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first charac
nvd
CVE-2018-11039P4MEDIUMCVSS 5.9fixed in 4.3.18≥ 5.0.0, < 5.0.72018-06-25
CVE-2018-11039 [MEDIUM] CVE-2018-11039: Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupport
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filt
nvd
CVE-2026-41841P4MEDIUMCVSS 5.9≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41841 [MEDIUM] CWE-524 CVE-2026-41841: Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41852P4MEDIUMCVSS 5.3≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41852 [MEDIUM] CWE-863 CVE-2026-41852: A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argu
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 throu
nvd
CVE-2020-5397P4MEDIUMCVSS 5.3≥ 5.2.0, < 5.2.32020-01-17
CVE-2020-5397 [MEDIUM] CWE-352 CVE-2020-5397: Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS prefligh
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail au
nvd
CVE-2023-20863P4MEDIUMCVSS 6.5≥ 5.2.0, < 5.2.24≥ 5.3.0, < 5.3.27+2 more2023-04-13
CVE-2023-20863 [MEDIUM] CWE-400 CVE-2023-20863: In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a use
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
nvd
CVE-2023-20861P4MEDIUMCVSS 6.5≤ 5.2.22≥ 5.3.0, ≤ 5.3.25+2 more2023-03-23
CVE-2023-20861 [MEDIUM] CWE-400 CVE-2023-20861: In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and olde
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
nvd
CVE-2018-1199P4MEDIUMCVSS 5.3≥ 4.3.0, < 4.3.14≥ 5.0.0, < 5.0.32018-03-16
CVE-2018-1199 [MEDIUM] CWE-20 CVE-2018-1199: Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The
nvd
CVE-2026-41844P4MEDIUMCVSS 6.1≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41844 [MEDIUM] CWE-601 CVE-2026-41844: A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name
A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3
nvd
CVE-2022-22970P4MEDIUMCVSS 5.3≤ 5.2.21≥ 5.3.0, ≤ 5.3.19+1 more2022-05-12
CVE-2022-22970 [MEDIUM] CWE-770 CVE-2022-22970: In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications t
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
nvd
CVE-2026-41840P4MEDIUMCVSS 5.9≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41840 [MEDIUM] CWE-400 CVE-2026-41840: Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multip
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.
Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
nvd
CVE-2026-41853P4MEDIUMCVSS 5.3≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41853 [MEDIUM] CWE-444 CVE-2026-41853: Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41847P4MEDIUMCVSS 5.3≥ 5.3.0, < 5.3.492026-06-09
CVE-2026-41847 [MEDIUM] CWE-284 CVE-2026-41847: Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Affected versions:
Spring Framework 5.3.0 through 5.3.48.
nvd
CVE-2026-41846P4MEDIUMCVSS 6.1≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41846 [MEDIUM] CWE-79 CVE-2026-41846: Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyl
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3
nvd
CVE-2015-0201P4MEDIUMCVSS 5.0v4.1.1v4.1.2+2 more2015-03-10
CVE-2015-0201 [MEDIUM] CWE-254 CVE-2015-0201: The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
nvd
CVE-2026-41845P4MEDIUMCVSS 6.1≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41845 [MEDIUM] CWE-79 CVE-2026-41845: Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code
Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd