目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-59326— Spring Tools for Eclipse 日志信息泄露漏洞

CVSS 3.3 · Low EPSS 0.10% · P1

可能的 ATT&CK 技术 1AI

T1530 · Data from Cloud Storage

影响版本矩阵 2

厂商产品版本范围状态
SpringSpring Tools for Eclipse≤ 5.2.0affected
SpringSpring Tools for VSCode / Cursor / Theia≤ 2.2.0affected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-59326 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server
来源: CVE Program / CVE List V5
Vulnerability Description
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form http://user:pass@proxy:8080, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Spring Tools for Eclipse 日志信息泄露漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Spring Spring Tools for Eclipse是美国Spring公司开源的一套软件开发工具插件。 Spring Tools for Eclipse 5.2.0及之前版本存在日志信息泄露漏洞,该漏洞源于Spring Boot language server在创建出站HTTP客户端且未配置显式http.proxy工作区设置时,以INFO级别记录https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY环境变量的原始值,可能导致代理凭证泄露。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
SpringSpring Tools for Eclipse 0 ~ 5.2.0 -
SpringSpring Tools for VSCode / Cursor / Theia 0 ~ 2.2.0 -

二、漏洞 CVE-2026-59326 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-59326 的情报信息

登录查看更多情报信息。

CVE-2026-59326 厂商安全公告 (1)

同批安全公告 · Spring · 2026-07-30 · 共 6 条

CVE-2026-478828.3 HIGHSpring Tools for Eclipse 加密问题漏洞
CVE-2026-478588.0 HIGHSpring Tools for Eclipse 授权问题漏洞
CVE-2026-478738.0 HIGHSpring Tools for Eclipse 配置错误漏洞
CVE-2026-593274.4 MEDIUMSpring Tools for Eclipse 加密问题漏洞
CVE-2026-593284.2 MEDIUMSpring Tools for Eclipse 跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-59326

暂无评论


发表评论