VMware

Spring Framework

90 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 27.08.2026 06:17:19
  • Zuletzt bearbeitet 10.09.2026 14:48:04

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

  • EPSS 0.32%
  • Veröffentlicht 27.08.2026 06:17:19
  • Zuletzt bearbeitet 10.09.2026 14:25:17

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Sprin...

  • EPSS 0.17%
  • Veröffentlicht 27.08.2026 06:17:19
  • Zuletzt bearbeitet 10.09.2026 14:19:58

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework ...

  • EPSS 0.32%
  • Veröffentlicht 27.08.2026 06:17:19
  • Zuletzt bearbeitet 10.09.2026 14:26:40

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Sprin...

  • EPSS 0.26%
  • Veröffentlicht 27.08.2026 06:17:18
  • Zuletzt bearbeitet 10.09.2026 14:06:46

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

  • EPSS 0.42%
  • Veröffentlicht 27.08.2026 06:17:18
  • Zuletzt bearbeitet 10.09.2026 14:11:26

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework...

  • EPSS 0.19%
  • Veröffentlicht 27.08.2026 06:17:18
  • Zuletzt bearbeitet 10.09.2026 14:54:50

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

  • EPSS 0.27%
  • Veröffentlicht 09.06.2026 03:51:57
  • Zuletzt bearbeitet 23.07.2026 08:10:00

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized a...

  • EPSS 0.12%
  • Veröffentlicht 09.06.2026 03:51:49
  • Zuletzt bearbeitet 23.07.2026 08:10:00

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7....

  • EPSS 0.19%
  • Veröffentlicht 09.06.2026 03:51:44
  • Zuletzt bearbeitet 23.07.2026 08:10:00

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.