Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Spring Framework — Vulnerabilities & Security Advisories 61

All 61 CVE vulnerabilities found in Spring Framework, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities affecting the Spring Framework, developed by VMware. It aggregates security issues spanning various CWE classifications, including injection flaws, cross-site scripting, and authentication bypasses, covering disclosures from January 2016 to the present. Users can utilize this resource to track vendor advisories issued by the Spring Security and Spring Boot teams, gain a deeper understanding of specific weakness classes within the Java ecosystem, and look up a product's comprehensive vulnerability history to assess long-term security trends. The collected data is sourced from official vendor communications, third-party security databases, and public disclosures, ensuring a robust view of the attack surface. By consolidating these entries, the page facilitates easier comparison of remediation efforts across different minor and major releases. It aims to provide developers and security professionals with a clear, chronological record of how the framework has evolved in response to emerging threats. This centralized view helps in identifying recurring patterns in code defects and evaluating the effectiveness of patching strategies over time. The information is presented without promotional language to maintain objectivity and utility for technical audits and risk assessments.

Vendor: Pivotal

CVE IDTitleCVSSSeverityPublished
CVE-2026-41855 Spring Framework Unsafe Deserialization via Jackson JMS Converters CWE-502 8.1 High2026-06-09
CVE-2026-41854 Spring Framework Server-Side Request Forgery via UriComponentsBuilder CWE-918 4.2 Medium2026-06-09
CVE-2026-41853 Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux CWE-444 5.3 Medium2026-06-09
CVE-2026-41852 Spring Framework Arbitrary Method Invocation in SpEL Expressions CWE-863 3.7 Low2026-06-09
CVE-2026-41851 Spring Framework Denial of Service via Unbounded Cache in SpEL CWE-770 5.3 Medium2026-06-09
CVE-2026-41850 Spring Framework Algorithmic Denial of Service via SpEL Expressions CWE-407 7.5 High2026-06-09
CVE-2026-41849 Spring Framework Denial of Service via Integer Overflow in SpEL Expressions CWE-190 7.5 High2026-06-09
CVE-2026-41848 Spring Framework Denial of Service via AntPathMatcher CWE-1333 3.7 Low2026-06-09
CVE-2026-41847 Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL CWE-284 4.8 Medium2026-06-09
CVE-2026-41846 Spring Framework Cross-site Scripting via JSP Form Tags CWE-79 5.9 Medium2026-06-09
CVE-2026-41845 Spring Framework Cross-site Scripting via JavaScriptUtils CWE-79 7.1 High2026-06-09
CVE-2026-41844 Spring Framework Open Redirect in Spring MVC and WebFlux CWE-601 4.2 Medium2026-06-09
CVE-2026-41843 Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux CWE-22 5.9 Medium2026-06-09
CVE-2026-41842 Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux CWE-400 7.5 High2026-06-09
CVE-2026-41841 Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux CWE-524 5.9 Medium2026-06-09
CVE-2026-41840 Spring Framework 资源管理错误漏洞 CWE-401 5.9 Medium2026-06-09
CVE-2026-41839 Spring Framework Escalation via Session Fixation in WebFlux CWE-384 4.2 Medium2026-06-09
CVE-2026-41838 Spring Framework Predictable Session ID in WebSocket Module CWE-330 4.8 Medium2026-06-09
CVE-2026-22745 CVE-2026-22745 : Denial of service in static resource handling on Windows platforms CWE-400 5.3 Medium2026-04-29
CVE-2026-22741 Static resource cache poisoning in Spring MVC and WebFlux CWE-524 3.1 Low2026-04-29
CVE-2026-22740 Spring Framework DoS with Multipart Temp Files in WebFlux CWE-400 6.5 Medium2026-04-29
CVE-2026-22737 Spring Framework Improper Path Limitation with Script View Templates 5.9 Medium2026-03-19
CVE-2025-41254 Spring Framework STOMP CSRF Vulnerability CWE-352 4.3 Medium2025-10-16
CVE-2025-41249 CVE-2025-41249: Spring Framework Annotation Detection Vulnerability 7.5 High2025-09-16
CVE-2025-41242 CVE-2025-41242: Path traversal vulnerability on non-compliant Servlet containers 5.9 Medium2025-08-18
CVE-2025-41234 RFD Attack via “Content-Disposition” Header Sourced from Request CWE-113 6.5 Medium2025-06-12
CVE-2025-22233 Spring Framework DataBinder Case Sensitive Match Exception CWE-20 3.1 Low2025-05-16
CVE-2024-38819 VMware Spring Framework 安全漏洞 CWE-22 7.5 High2024-12-19
CVE-2024-38809 VMware Spring Framework 安全漏洞 5.3 Medium2024-09-27
CVE-2024-38808 CVE-2024-38808: Spring Expression DoS Vulnerability 4.3 Medium2024-08-20

All 61 known CVE vulnerabilities affecting Spring Framework with full Chinese analysis, references, and POCs where available.