Spring Framework
18 known vulnerabilities in Spring Framework, 7 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2022-22965 CVSS 9.8 critical · actively exploited Spring Framework JDK 9+ Remote Code Execution Vulnerability
Latest vulnerabilities
- CVE-2026-59314 CVSS 3.7 low Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the…
- CVE-2026-59313 CVSS 9.8 critical Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring…
- CVE-2026-59283 CVSS 9.1 critical Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard…
- CVE-2026-59282 CVSS 7.5 high Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may…
- CVE-2026-59281 CVSS 6.1 medium Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors…
- CVE-2026-59280 CVSS 4.3 medium Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view…
- CVE-2026-47893 CVSS 7.5 high A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request…
- CVE-2026-47892 CVSS 9.8 critical A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a…
- CVE-2026-47891 CVSS 9.8 critical A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize…
- CVE-2026-47890 CVSS 9.8 critical Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring…
- CVE-2026-47889 CVSS 7.5 high A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring…
- CVE-2026-47888 CVSS 7.5 high A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework…
- CVE-2026-47887 CVSS 6.1 medium A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is…
- CVE-2026-47886 CVSS 7.5 high Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS)…
- CVE-2026-47885 CVSS 7.5 high The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring…
- CVE-2026-47884 CVSS 9.8 critical Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view…
- CVE-2026-47883 CVSS 6.1 medium UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the…
- CVE-2022-22965 CVSS 9.8 critical · actively exploited Spring Framework JDK 9+ Remote Code Execution Vulnerability