Vmware Spring Framework vulnerabilities
87 known vulnerabilities affecting vmware/spring_framework.
Total CVEs
87
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH27MEDIUM45LOW3
Vulnerabilities
Page 5 of 5
CVE-2025-41254P4MEDIUMCVSS 4.3v5.3.xv6.0.x+2 more2025-10-16
CVE-2025-41254 [MEDIUM] CWE-352 CVE-2025-41254: STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to
STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages.
Affected Spring Products and VersionsSpring Framework:
* 6.2.0 - 6.2.11
* 6.1.0 - 6.1.23
* 6.0.x - 6.0.29
* 5.3.0 - 5.3.45
* Older, unsupported versions are also affected.
MitigationUsers of affected versions should upgr
nvd
CVE-2021-22060P4MEDIUMCVSS 4.3≥ 5.2.0, ≤ 5.2.18≥ 5.3.0, ≤ 5.3.13+1 more2022-01-10
CVE-2021-22060 [MEDIUM] CVE-2021-22060: In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is p
In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.
nvd
CVE-2026-41839P4MEDIUMCVSS 4.2fixed in 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41839 [MEDIUM] CWE-384 CVE-2026-41839: A WebFlux application with a compromised subdomain (for example, compromised via cross-site scriptin
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2024-38808P4MEDIUMCVSS 4.3≥ 5.3.0, < 5.3.392024-08-20
CVE-2024-38808 [MEDIUM] CWE-770 CVE-2024-38808: In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a use
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.
Specifically, an application is vulnerable when the following is true:
* The application evaluates user-supplied SpEL e
nvd
CVE-2026-59314P4LOWCVSS 3.7≤ 5.2.25≥ 5.3.0, ≤ 5.3.49+4 more2026-08-27
CVE-2026-59314 [LOW] CWE-113 CVE-2026-59314: Applications that build a Content-Disposition header value from untrusted input may be vulnerable to
Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEA
nvd
CVE-2026-22735P4LOWCVSS 2.6fixed in 5.3.47≥ 6.1.0, < 6.1.26+2 more2026-03-20
CVE-2026-22735 [LOW] CWE-667 CVE-2026-22735: Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Event
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
nvd
CVE-2026-22741P4LOWCVSS 3.1fixed in 5.3.48≥ 6.1.0, < 6.1.27+3 more2026-04-29
CVE-2026-22741 [LOW] CWE-524 CVE-2026-22741: Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resource
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
More precisely, an application can be vulnerable when all the following are true:
* the application is using Spring MVC or Spring WebFlux
* the application is configuring the resource chain support https://docs.spring.io/spring-framework/reference/
nvd
← Previous5 / 5