CVE-2026-59326
- EPSS 0.1%
- Veröffentlicht 30.07.2026 06:25:55
- Zuletzt bearbeitet 08.09.2026 20:06:39
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corpora...
CVE-2026-59327
- EPSS 0.09%
- Veröffentlicht 30.07.2026 06:25:55
- Zuletzt bearbeitet 30.09.2026 18:39:34
Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartex...
CVE-2026-59328
- EPSS 0.16%
- Veröffentlicht 30.07.2026 06:25:55
- Zuletzt bearbeitet 30.09.2026 18:35:03
Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in ...
- EPSS 0.18%
- Veröffentlicht 30.07.2026 06:25:52
- Zuletzt bearbeitet 30.09.2026 18:38:43
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0...
CVE-2026-47882
- EPSS 0.17%
- Veröffentlicht 30.07.2026 06:25:52
- Zuletzt bearbeitet 30.09.2026 18:38:07
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart u...
- EPSS 0.2%
- Veröffentlicht 30.07.2026 05:15:31
- Zuletzt bearbeitet 08.09.2026 20:06:31
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and ...