Vmware Spring Framework vulnerabilities
87 known vulnerabilities affecting vmware/spring_framework.
Total CVEs
87
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH27MEDIUM45LOW3
Vulnerabilities
Page 4 of 5
CVE-2020-5397P4MEDIUMCVSS 5.3≥ 5.2.0, < 5.2.32020-01-17
CVE-2020-5397 [MEDIUM] CWE-352 CVE-2020-5397: Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS prefligh
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail au
nvd
CVE-2023-20863P4MEDIUMCVSS 6.5≥ 5.2.0, < 5.2.24≥ 5.3.0, < 5.3.27+2 more2023-04-13
CVE-2023-20863 [MEDIUM] CWE-400 CVE-2023-20863: In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a use
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
nvd
CVE-2023-20861P4MEDIUMCVSS 6.5≤ 5.2.22≥ 5.3.0, ≤ 5.3.25+2 more2023-03-23
CVE-2023-20861 [MEDIUM] CWE-400 CVE-2023-20861: In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and olde
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
nvd
CVE-2018-1199P4MEDIUMCVSS 5.3≥ 4.3.0, < 4.3.14≥ 5.0.0, < 5.0.32018-03-16
CVE-2018-1199 [MEDIUM] CWE-20 CVE-2018-1199: Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The
nvd
CVE-2026-41844P4MEDIUMCVSS 6.1≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41844 [MEDIUM] CWE-601 CVE-2026-41844: A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name
A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3
nvd
CVE-2022-22970P4MEDIUMCVSS 5.3≤ 5.2.21≥ 5.3.0, ≤ 5.3.19+1 more2022-05-12
CVE-2022-22970 [MEDIUM] CWE-770 CVE-2022-22970: In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications t
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
nvd
CVE-2026-41840P4MEDIUMCVSS 5.9≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41840 [MEDIUM] CWE-400 CVE-2026-41840: Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multip
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.
Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
nvd
CVE-2026-41853P4MEDIUMCVSS 5.3≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41853 [MEDIUM] CWE-444 CVE-2026-41853: Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-41847P4MEDIUMCVSS 5.3≥ 5.3.0, < 5.3.492026-06-09
CVE-2026-41847 [MEDIUM] CWE-284 CVE-2026-41847: Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Affected versions:
Spring Framework 5.3.0 through 5.3.48.
nvd
CVE-2026-59281P4MEDIUMCVSS 6.1fixed in 5.2.26≥ 5.3.0, < 5.3.50+4 more2026-08-27
CVE-2026-59281 [MEDIUM] CWE-79 CVE-2026-59281: Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping en
Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors are vulnerable to arbitrary HTML/JavaScript code injection, potentially resulting in a reflected cross-site scripting (XSS) vulnerabili
nvd
CVE-2026-47887P4MEDIUMCVSS 6.1fixed in 5.2.26≥ 5.3.0, < 5.3.50+4 more2026-08-27
CVE-2026-47887 [MEDIUM] CWE-601 CVE-2026-47887: A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.2
nvd
CVE-2026-41846P4MEDIUMCVSS 6.1≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41846 [MEDIUM] CWE-79 CVE-2026-41846: Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyl
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3
nvd
CVE-2015-0201P4MEDIUMCVSS 5.0v4.1.1v4.1.2+2 more2015-03-10
CVE-2015-0201 [MEDIUM] CWE-254 CVE-2015-0201: The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
nvd
CVE-2026-41845P4MEDIUMCVSS 6.1≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41845 [MEDIUM] CWE-79 CVE-2026-41845: Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code
Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2026-22745P4MEDIUMCVSS 5.3fixed in 5.3.48≥ 6.1.0, < 6.1.27+3 more2026-04-29
CVE-2026-22745 [MEDIUM] CWE-400 CVE-2026-22745: Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving stati
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources.
More precisely, an application can be vulnerable when all the following are true:
* the application is using Spring MVC or Spring WebFlux
* the application is serving static resources from the file system
* the application is running o
nvd
CVE-2026-47883P4MEDIUMCVSS 6.1≥ 6.2.0, < 6.2.20≥ 7.0.0, < 7.0.8.12026-08-27
CVE-2026-47883 [MEDIUM] CWE-601 CVE-2026-47883: UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching pa
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
nvd
CVE-2024-38820P4MEDIUMCVSS 5.3≥ 5.3.0, < 5.3.41≥ 6.0.0, < 6.0.25+1 more2024-10-18
CVE-2024-38820 [MEDIUM] CWE-178 CVE-2024-38820: The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, S
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
nvd
CVE-2026-59280P4MEDIUMCVSS 4.3fixed in 5.2.26≥ 5.3.0, < 5.3.50+4 more2026-08-27
CVE-2026-59280 [MEDIUM] CWE-22 CVE-2026-59280: Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal a
Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spri
nvd
CVE-2021-22096P4MEDIUMCVSS 4.3≥ 5.2.0, ≤ 5.2.17≥ 5.3.0, ≤ 5.3.10+1 more2021-10-28
CVE-2021-22096 [MEDIUM] CWE-117 CVE-2021-22096: In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is p
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
nvd
CVE-2015-3192P4MEDIUMCVSS 5.5v3.2.1v3.2.2+17 more2016-07-12
CVE-2015-3192 [MEDIUM] CWE-119 CVE-2015-3192: Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD decla
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
nvd