Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42900
Total
3476
Critical
12865
High
12603
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59274 | MEDIUM | 6.5 | The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust … | Aug 27, 2026 |
| CVE-2026-59271 | MEDIUM | 5.3 | When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP … | Aug 27, 2026 |
| CVE-2026-59270 | CRITICAL | 9.4 | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring … | Aug 27, 2026 |
| CVE-2026-47894 | MEDIUM | 4.9 | Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring … | Aug 27, 2026 |
| CVE-2026-47893 | UNKNOWN | — | A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 … | Aug 27, 2026 |
| CVE-2026-47892 | UNKNOWN | — | A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 … | Aug 27, 2026 |
| CVE-2026-47891 | CRITICAL | 9.8 | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 … | Aug 27, 2026 |
| CVE-2026-47890 | CRITICAL | 9.8 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework … | Aug 27, 2026 |
| CVE-2026-47889 | HIGH | 7.5 | A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework … | Aug 27, 2026 |
| CVE-2026-47888 | HIGH | 7.5 | A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 … | Aug 27, 2026 |
| CVE-2026-47887 | MEDIUM | 6.1 | A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open … | Aug 27, 2026 |
| CVE-2026-47886 | HIGH | 7.5 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is … | Aug 27, 2026 |
| CVE-2026-47885 | HIGH | 7.5 | The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 … | Aug 27, 2026 |
| CVE-2026-47884 | CRITICAL | 9.8 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in … | Aug 27, 2026 |
| CVE-2026-47883 | MEDIUM | 6.1 | UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring … | Aug 27, 2026 |
| CVE-2026-47881 | MEDIUM | 5.9 | Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for example, a CSV field that contains embedded newlines wrapped … | Aug 27, 2026 |
| CVE-2026-47880 | MEDIUM | 5.4 | A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, … | Aug 27, 2026 |
| CVE-2026-47879 | HIGH | 7.7 | Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - … | Aug 27, 2026 |
| CVE-2026-47878 | MEDIUM | 5.6 | DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted … | Aug 27, 2026 |
| CVE-2026-47877 | HIGH | 8.2 | Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 | Aug 27, 2026 |
| CVE-2026-47875 | MEDIUM | 5.6 | Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The … | Aug 27, 2026 |
| CVE-2026-47864 | MEDIUM | 6.4 | SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to … | Aug 27, 2026 |
| CVE-2026-47849 | HIGH | 7.1 | Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 … | Aug 27, 2026 |
| CVE-2026-19715 | HIGH | 7.5 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is … | Aug 27, 2026 |
| CVE-2026-19454 | MEDIUM | 4.4 | The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the … | Aug 27, 2026 |