vmware / spring_framework
38 known vulnerabilities in vmware spring_framework.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2018-15756 | Medium | 9.2% | 7.5 | Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x pr… | |
| CVE-2018-1258 | Medium | 2.5% | 8.8 | Spring Framework version 5.0.5 when used in combination with any versions of Spr… | |
| CVE-2026-47884 | Medium | 0.4% | 9.8 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if… | |
| CVE-2026-41842 | Medium | 0.4% | 7.5 | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) at… | |
| CVE-2026-59313 | Medium | 0.4% | 9.8 | Spring MVC applications using the functional web framework are vulnerable to str… | |
| CVE-2026-59283 | Medium | 0.4% | 9.1 | Applications that evaluate Spring Expression Language (SpEL) expressions using S… | |
| CVE-2026-47892 | Medium | 0.4% | 9.8 | A WebFlux application using functional endpoints and deployed with DispatcherSer… | |
| CVE-2026-41850 | Medium | 0.4% | 7.5 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expre… | |
| CVE-2026-47886 | Medium | 0.3% | 7.5 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expre… | |
| CVE-2026-47888 | Medium | 0.3% | 7.5 | A Spring RSocket application is exposed to a memory leak via a malformed SETUP f… | |
| CVE-2026-59282 | Medium | 0.3% | 7.5 | Spring Framework applications that use Spring's data binding infrastructure to a… | |
| CVE-2026-47890 | Medium | 0.3% | 9.8 | Spring MVC and WebFlux applications are vulnerable to stream corruption when usi… | |
| CVE-2026-47891 | Medium | 0.3% | 9.8 | A Spring WebFlux application that relies on the Aalto XML processor to parse XML… | |
| CVE-2026-41855 | Medium | 0.3% | 8.1 | In an untrusted JMS environment, org.springframework.jms.support.converter.Mappi… | |
| CVE-2026-41849 | Medium | 0.3% | 7.5 | An integer overflow vulnerability exists in the evaluation logic of the Spring E… | |
| CVE-2026-47885 | Medium | 0.3% | 7.5 | The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSiz… | |
| CVE-2026-47889 | Medium | 0.3% | 7.5 | A WebFlux application running on the Jetty 12 Core reactive adapter serializes r… | |
| CVE-2026-47893 | Medium | 0.2% | 7.5 | A Spring WebFlux application that supports WebSocket connections may expose indi… | |
| CVE-2026-41845 | Medium | 0.2% | 7.1 | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lea… | |
| CVE-2018-11039 | Low | 2.7% | 5.9 | Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18,… | |
| CVE-2026-41843 | Low | 0.4% | 5.9 | Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks whe… | |
| CVE-2026-41851 | Low | 0.4% | 5.3 | Applications which accept user-supplied Spring Expression Language (SpEL) expres… | |
| CVE-2026-41841 | Low | 0.3% | 5.9 | Spring MVC and WebFlux applications are vulnerable to Information Disclosure att… | |
| CVE-2026-41848 | Low | 0.3% | 3.7 | Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS)… | |
| CVE-2026-41840 | Low | 0.3% | 5.9 | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks wh… | |
| CVE-2026-59280 | Low | 0.2% | 4.3 | Applications using Spring Framework's FreeMarker integration may be vulnerable t… | |
| CVE-2026-41839 | Low | 0.2% | 4.2 | A WebFlux application with a compromised subdomain (for example, compromised via… | |
| CVE-2026-59314 | Low | 0.2% | 3.7 | Applications that build a Content-Disposition header value from untrusted input … | |
| CVE-2026-47883 | Low | 0.2% | 6.1 | UrlHandlerFilter can be vulnerable to an open redirect when configured with very… | |
| CVE-2026-41853 | Low | 0.2% | 5.3 | Spring MVC and WebFlux applications are vulnerable to Multipart request smugglin… | |
| CVE-2026-59281 | Low | 0.2% | 6.1 | Spring MVC and WebFlux applications that obtain a data-binding Errors instance w… | |
| CVE-2026-41852 | Low | 0.2% | 3.7 | A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for… | |
| CVE-2026-47887 | Low | 0.2% | 6.1 | A Spring MVC application that uses UrlFileNameViewController that is mapped with… | |
| CVE-2026-41838 | Low | 0.2% | 4.8 | IDs for WebSocket sessions in the spring-websocket module are not cryptographica… | |
| CVE-2026-41847 | Low | 0.2% | 4.8 | Spring WebFlux applications may be vulnerable to a security bypass when using th… | |
| CVE-2026-41846 | Low | 0.2% | 5.9 | Spring MVC applications which accept user-supplied values in the cssClass, cssEr… | |
| CVE-2026-41844 | Low | 0.1% | 4.2 | A Spring MVC or Spring WebFlux application which configures a mapping for "/**" … | |
| CVE-2026-41854 | Low | 0.1% | 4.2 | Due to incorrect host parsing, applications that rely on UriComponentsBuilder to… |