Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Spring Framework — Vulnerabilities & Security Advisories 61

All 61 CVE vulnerabilities found in Spring Framework, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities identified in the Spring Framework, a popular Java-based framework for building enterprise applications, categorized under common weakness types and relevant security tags. It compiles a comprehensive list of security issues affecting this specific software product, covering reported vulnerabilities from early releases through to the most recent updates. By visiting this resource, users can effectively track official advisories issued by the Spring Security team, gain a deeper understanding of specific weakness classes such as deserialization flaws or injection attacks, and explore the historical pattern of vulnerabilities associated with different versions of the framework. This aggregation serves as a centralized reference point for developers, security analysts, and system administrators who need to assess risk and prioritize patches. The data presented here is sourced from official vendor notifications, third-party security databases, and community reports, ensuring a broad perspective on the security posture of Spring applications. Understanding these aggregated trends helps teams proactively address known weaknesses before they can be exploited in production environments. Whether you are conducting a security audit, performing routine maintenance, or researching the impact of specific CVEs on your infrastructure, this page provides the necessary context to make informed decisions. It highlights recurring themes in vulnerability reports, allowing for better long-term strategic planning regarding code reviews and dependency management within Spring-based projects.

Vendor: Pivotal

CVE IDTitleCVSSSeverityPublished
CVE-2026-41855 Spring Framework Unsafe Deserialization via Jackson JMS Converters CWE-502 8.1 High2026-06-09
CVE-2026-41854 Spring Framework Server-Side Request Forgery via UriComponentsBuilder CWE-918 4.2 Medium2026-06-09
CVE-2026-41853 Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux CWE-444 5.3 Medium2026-06-09
CVE-2026-41852 Spring Framework Arbitrary Method Invocation in SpEL Expressions CWE-863 3.7 Low2026-06-09
CVE-2026-41851 Spring Framework Denial of Service via Unbounded Cache in SpEL CWE-770 5.3 Medium2026-06-09
CVE-2026-41850 Spring Framework Algorithmic Denial of Service via SpEL Expressions CWE-407 7.5 High2026-06-09
CVE-2026-41849 Spring Framework Denial of Service via Integer Overflow in SpEL Expressions CWE-190 7.5 High2026-06-09
CVE-2026-41848 Spring Framework Denial of Service via AntPathMatcher CWE-1333 3.7 Low2026-06-09
CVE-2026-41847 Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL CWE-284 4.8 Medium2026-06-09
CVE-2026-41846 Spring Framework Cross-site Scripting via JSP Form Tags CWE-79 5.9 Medium2026-06-09
CVE-2026-41845 Spring Framework Cross-site Scripting via JavaScriptUtils CWE-79 7.1 High2026-06-09
CVE-2026-41844 Spring Framework Open Redirect in Spring MVC and WebFlux CWE-601 4.2 Medium2026-06-09
CVE-2026-41843 Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux CWE-22 5.9 Medium2026-06-09
CVE-2026-41842 Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux CWE-400 7.5 High2026-06-09
CVE-2026-41841 Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux CWE-524 5.9 Medium2026-06-09
CVE-2026-41840 Spring Framework 资源管理错误漏洞 CWE-401 5.9 Medium2026-06-09
CVE-2026-41839 Spring Framework Escalation via Session Fixation in WebFlux CWE-384 4.2 Medium2026-06-09
CVE-2026-41838 Spring Framework Predictable Session ID in WebSocket Module CWE-330 4.8 Medium2026-06-09
CVE-2026-22745 CVE-2026-22745 : Denial of service in static resource handling on Windows platforms CWE-400 5.3 Medium2026-04-29
CVE-2026-22741 Static resource cache poisoning in Spring MVC and WebFlux CWE-524 3.1 Low2026-04-29
CVE-2026-22740 Spring Framework DoS with Multipart Temp Files in WebFlux CWE-400 6.5 Medium2026-04-29
CVE-2026-22737 Spring Framework Improper Path Limitation with Script View Templates 5.9 Medium2026-03-19
CVE-2025-41254 Spring Framework STOMP CSRF Vulnerability CWE-352 4.3 Medium2025-10-16
CVE-2025-41249 CVE-2025-41249: Spring Framework Annotation Detection Vulnerability 7.5 High2025-09-16
CVE-2025-41242 CVE-2025-41242: Path traversal vulnerability on non-compliant Servlet containers 5.9 Medium2025-08-18
CVE-2025-41234 RFD Attack via “Content-Disposition” Header Sourced from Request CWE-113 6.5 Medium2025-06-12
CVE-2025-22233 Spring Framework DataBinder Case Sensitive Match Exception CWE-20 3.1 Low2025-05-16
CVE-2024-38819 VMware Spring Framework 安全漏洞 CWE-22 7.5 High2024-12-19
CVE-2024-38809 VMware Spring Framework 安全漏洞 5.3 Medium2024-09-27
CVE-2024-38808 CVE-2024-38808: Spring Expression DoS Vulnerability 4.3 Medium2024-08-20

All 61 known CVE vulnerabilities affecting Spring Framework with full Chinese analysis, references, and POCs where available.