cbcvebase.

Vmware Spring Framework vulnerabilities

70 known vulnerabilities affecting vmware/spring_framework.

Total CVEs
70
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH21MEDIUM41LOW2

Vulnerabilities

Page 4 of 4
CVE-2026-22745P4MEDIUMCVSS 5.3fixed in 5.3.48≥ 6.1.0, < 6.1.27+3 more2026-04-29
CVE-2026-22745 [MEDIUM] CWE-400 CVE-2026-22745: Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving stati Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running o
nvd
CVE-2024-38820P4MEDIUMCVSS 5.3≥ 5.3.0, < 5.3.41≥ 6.0.0, < 6.0.25+1 more2024-10-18
CVE-2024-38820 [MEDIUM] CWE-178 CVE-2024-38820: The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, S The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
nvd
CVE-2021-22096P4MEDIUMCVSS 4.3≥ 5.2.0, ≤ 5.2.17≥ 5.3.0, ≤ 5.3.10+1 more2021-10-28
CVE-2021-22096 [MEDIUM] CWE-117 CVE-2021-22096: In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is p In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
nvd
CVE-2025-41254P4MEDIUMCVSS 4.3v5.3.xv6.0.x+2 more2025-10-16
CVE-2025-41254 [MEDIUM] CWE-352 CVE-2025-41254: STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: * 6.2.0 - 6.2.11 * 6.1.0 - 6.1.23 * 6.0.x - 6.0.29 * 5.3.0 - 5.3.45 * Older, unsupported versions are also affected. MitigationUsers of affected versions should upgr
nvd
CVE-2015-3192P4MEDIUMCVSS 5.5v3.2.1v3.2.2+17 more2016-07-12
CVE-2015-3192 [MEDIUM] CWE-119 CVE-2015-3192: Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD decla Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
nvd
CVE-2021-22060P4MEDIUMCVSS 4.3≥ 5.2.0, ≤ 5.2.18≥ 5.3.0, ≤ 5.3.13+1 more2022-01-10
CVE-2021-22060 [MEDIUM] CVE-2021-22060: In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is p In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.
nvd
CVE-2026-41839P4MEDIUMCVSS 4.2fixed in 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41839 [MEDIUM] CWE-384 CVE-2026-41839: A WebFlux application with a compromised subdomain (for example, compromised via cross-site scriptin A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2024-38808P4MEDIUMCVSS 4.3≥ 5.3.0, < 5.3.392024-08-20
CVE-2024-38808 [MEDIUM] CWE-770 CVE-2024-38808: In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a use In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL e
nvd
CVE-2026-22735P4LOWCVSS 2.6fixed in 5.3.47≥ 6.1.0, < 6.1.26+2 more2026-03-20
CVE-2026-22735 [LOW] CWE-667 CVE-2026-22735: Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Event Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
nvd
CVE-2026-22741P4LOWCVSS 3.1fixed in 5.3.48≥ 6.1.0, < 6.1.27+3 more2026-04-29
CVE-2026-22741 [LOW] CWE-524 CVE-2026-22741: Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resource Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the resource chain support https://docs.spring.io/spring-framework/reference/
nvd
Vmware Spring Framework vulnerabilities | cvebase