CVE-2026-59324fluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunction Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/27/2026 Severity High CVE-2026-59322EmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeaders Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/27/2026 Severity Medium CVE-2026-59321Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/27/2026 Severity Medium CVE-2026-59320In Spring AMQP the link credit never replenished on listener exception path Exploitation status Not known exploited Fix Not confirmed Affected product S Spring AMQP Published 08/27/2026 Severity Medium CVE-2026-59319RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data Exposure Exploitation status Not known exploited Fix Not confirmed Affected product S Spring AI Published 08/27/2026 Severity Medium CVE-2026-59317In Spring for Apache Kafka, missing header validation in DeadLetterPublishingRecovererFactory enables denial of service via a poison-pill loop Exploitation status Not known exploited Fix YesAffected product S Spring For Apache Kafka Published 08/27/2026 Severity Medium CVE-2026-59316Spring Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS) Exploitation status Not known exploited Fix YesAffected product S Spring Authorization Server Published 08/27/2026 Severity High CVE-2026-59315Spring Cloud Config Monitor Denial of Service Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Config Published 08/27/2026 Severity Medium CVE-2026-59314Spring Framework response splitting in ContentDisposition Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity Low CVE-2026-59311Fixed predictable /tmp/ziptransformer work directory enables symlink pre-creation Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/27/2026 Severity Medium CVE-2026-59306Potential for deserialization of untrusted types in Spring Cloud Stream Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Stream Published 08/27/2026 Severity Low CVE-2026-59313Server Sent Event stream corruption in Spring MVC functional web framework Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity Critical CVE-2026-59307Deserialization allow-list silently bypassed: setBeanClassLoader replaces deserializer but mapper keeps stale reference Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/27/2026 Severity High CVE-2026-59305Partition interceptor may be improperly added while sending message Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Stream Published 08/27/2026 Severity Low CVE-2026-59304Improper caching of the original content type in Spring Cloud Stream Avro Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Stream Published 08/27/2026 Severity Low CVE-2026-59303Dynamic destination cache size is not properly bound in Spring Cloud Stream Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Stream Published 08/27/2026 Severity Low CVE-2026-59302Potential for logging sensitive data in Spring Cloud Stream Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Stream Published 08/27/2026 Severity Low CVE-2026-59301Potential for logging sensitive data in Spring Cloud Function Azure Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Function Published 08/27/2026 Severity Low CVE-2026-59300Potential for logging sensitive data in Spring Cloud Function AWS Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Function Published 08/27/2026 Severity Low CVE-2026-59299Composition lookup can potentially poison base function in Spring Cloud Function Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Function Published 08/27/2026 Severity Low CVE-2026-59298Potential for improper filtering of HTTP headers in Spring Cloud Function Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Function Published 08/27/2026 Severity Low CVE-2026-59297Spring Cloud Function can incorrectly determine if URI is secure Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Function Published 08/27/2026 Severity Low CVE-2026-59294Arbitrary File Write via Path Traversal in ResourceCacheService Exploitation status Not known exploited Fix YesAffected product S Spring AI Published 08/27/2026 Severity Medium CVE-2026-59293SMB minimum protocol dialect defaults to SMB1 Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/27/2026 Severity Medium CVE-2026-59292World-readable metadata file in PropertiesPersistingMetadataStore (insecure temp-file permissions) Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/27/2026 Severity Low CVE-2026-59291Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Function Published 08/27/2026 Severity Low CVE-2026-59289Spring for GraphQL Denial of Service via pagination support Exploitation status Not known exploited Fix YesAffected product S Spring for GraphQL Published 08/27/2026 Severity High CVE-2026-59288Spring for GraphQL Information Exposure in GraphiQL support Exploitation status Not known exploited Fix YesAffected product S Spring for GraphQL Published 08/27/2026 Severity High CVE-2026-59287Spring for GraphQL WebSocket Client Denial of Service Exploitation status Not known exploited Fix YesAffected product S Spring for GraphQL Published 08/27/2026 Severity Medium CVE-2026-59286Spring for GraphQL loads Untrusted Resources in GraphiQL support Exploitation status Not known exploited Fix YesAffected product S Spring for GraphQL Published 08/27/2026 Severity High CVE-2026-59285Spring for GraphQL Unsafe Deserialization in pagination support Exploitation status Not known exploited Fix YesAffected product S Spring for GraphQL Published 08/27/2026 Severity High CVE-2026-59284Spring Cloud Commons no allow list for writable env actuator endpoint Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Commons Published 08/27/2026 Severity Medium CVE-2026-59283Spring Framework Safety Guard Bypass via SpEL Expression Compilation Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity Critical CVE-2026-59282Spring Framework Denial of Service via Unbounded List Growth in Data Binding Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity High CVE-2026-59281Spring Framework Cross-site Scripting via EscapedErrors Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity Medium CVE-2026-59277Spring Security InetAddressMatchers Incomplete Internal Network Classification Exploitation status Not known exploited Fix Not confirmed Affected product S Spring Security Published 08/27/2026 Severity Low CVE-2026-59276Timing Attack via Non-Constant-Time Comparison of Sensitive Values Exploitation status Not known exploited Fix YesAffected product S Spring Security Published 08/27/2026 Severity Medium CVE-2026-59280Spring Framework Path Traversal via Backslash in SpringTemplateLoader Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity Medium CVE-2026-59272Log4j2 AmqpAppender disables TLS hostname verification by default Exploitation status Not known exploited Fix YesAffected product S Spring AMQP Published 08/27/2026 Severity Medium CVE-2026-47893Spring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketService Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity High CVE-2026-47892Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity Critical CVE-2026-47891Spring Framework maxInMemorySize Bypassed in Jaxb2Decoder Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity Critical CVE-2026-47890Spring Framework Server Sent Event stream corruption while rendering fragments Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity Critical CVE-2026-47889Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity High CVE-2026-47888Spring Framework Memory Leak via SETUP Frame in RSocketMessageHandler Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity High CVE-2026-47887Spring Framework Open Redirect in UrlFileNameViewController Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity Medium CVE-2026-47886Spring Framework Denial of Service via Unbounded Exponentiation in SpEL Expressions Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity High CVE-2026-47885Spring Framework maxPartSize Ignored in PartEventHttpMessageReader Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity High CVE-2026-47884Spring Framework Improper Path Limitation in XsltView Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity Critical CVE-2026-47883Spring Framework Open Redirect in UrlHandlerFilter Exploitation status Not known exploited Fix YesAffected product S Spring Framework Published 08/27/2026 Severity Medium CVE-2026-59278In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types in header mapper default trusted packages Exploitation status Not known exploited Fix YesAffected product S Spring For Apache Kafka Published 08/27/2026 Severity Medium CVE-2026-59275Remote JVM termination: nested-array Java deserialization bypasses allowlist, triggers StackOverflowError, default JavaLangErrorHandler calls System.exit(99) Exploitation status Not known exploited Fix YesAffected product S Spring AMQP Published 08/27/2026 Severity Medium CVE-2026-59274Unbounded decompression in UnZipTransformer enables zip-bomb DoS Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/27/2026 Severity Medium CVE-2026-59271Admin password disclosed in BrokerNotAliveException message Exploitation status Not known exploited Fix YesAffected product S Spring AMQP Published 08/27/2026 Severity Medium CVE-2026-59270Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces Exploitation status Not known exploited Fix YesAffected product S Spring Security Published 08/27/2026 Severity Critical CVE-2026-47894Spring Cloud Config Server Native Environment Repository Exposure Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Config Published 08/27/2026 Severity Medium CVE-2026-47881Denial of Service in Spring Batch FlatFileItemReader via Malformed Input File Exploitation status Not known exploited Fix YesAffected product S Spring Batch Published 08/27/2026 Severity Medium CVE-2026-47880DefaultJmsHeaderMapper copies all JMS user properties into MessageHeaders without excluding framework-significant names Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/27/2026 Severity Medium CVE-2026-47879Spring Cloud Gateway SSRF and native file access with gRPC Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Gateway Published 08/27/2026 Severity High CVE-2026-47878Unsafe Java deserialization in DefaultExecutionContextSerializer without class allowlist Exploitation status Not known exploited Fix YesAffected product S Spring Batch Published 08/27/2026 Severity Medium CVE-2026-47877Spring Security Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS) Exploitation status Not known exploited Fix YesAffected product S Spring Security Published 08/27/2026 Severity High CVE-2026-47875JobParameterDeserializer bypasses the trusted-type allowlist Exploitation status Not known exploited Fix YesAffected product S Spring Batch Published 08/27/2026 Severity Medium CVE-2026-47864Unsafe Java deserialization in SerializingHttpMessageConverter — remote code execution Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/27/2026 Severity Medium CVE-2026-47849Spring Data REST allows mutation of identifier and version properties via JSON Patch Exploitation status Not known exploited Fix YesAffected product S Spring Data REST Published 08/27/2026 Severity High CVE-2026-47874Reactor Netty HTTP Server Denial of Service With Pipelined Requests Exploitation status Not known exploited Fix YesAffected product R Reactor Netty Published 08/26/2026 Severity Medium CVE-2026-47861UDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when acknowledge=false Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/26/2026 Severity Medium CVE-2026-47863Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream delivers items during an active flush Exploitation status Not known exploited Fix YesAffected product R Reactor Core Published 08/26/2026 Severity Medium CVE-2026-47862ZipTransformer uses file_name header to build workDirectory path without sanitization Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/26/2026 Severity Medium CVE-2026-47860Unbounded decompression of attacker-supplied compressed message bodies Exploitation status Not known exploited Fix YesAffected product S Spring AMQP Published 08/26/2026 Severity Medium CVE-2026-47859Unbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoS Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/26/2026 Severity Medium CVE-2026-47857Reactor Core windowTimeout fair-backpressure stream hang due to 20-bit index wrap-around Exploitation status Not known exploited Fix YesAffected product R Reactor Core Published 08/26/2026 Severity Medium CVE-2026-47856JsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-list Exploitation status Not known exploited Fix YesAffected product S Spring Integration Published 08/26/2026 Severity Medium CVE-2026-47852Predictable cache directory location allows local ONNX model substitution in Spring AI Exploitation status Not known exploited Fix YesAffected product S Spring AI Published 08/26/2026 Severity High CVE-2026-47851Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader Exploitation status Not known exploited Fix YesAffected product S Spring AI Published 08/26/2026 Severity High CVE-2026-47850Spring Data REST allows mutation of the version property of immutable aggregates via PUT Exploitation status Not known exploited Fix YesAffected product S Spring Data REST Published 08/26/2026 Severity Medium CVE-2026-47845Reactor Netty HTTP Server may incorrectly evaluate proxy addresses Exploitation status Not known exploited Fix YesAffected product R Reactor Netty Published 08/26/2026 Severity Medium CVE-2026-47848Reactor Netty WebSocket Client Leaks Credentials On Redirect Exploitation status Not known exploited Fix YesAffected product R Reactor Netty Published 08/26/2026 Severity Medium CVE-2026-47844Reactor Netty HTTP Server Leaks Exception Details Exploitation status Not known exploited Fix YesAffected product R Reactor Netty Published 08/26/2026 Severity Medium CVE-2026-47843Reactor Netty may incorrectly route traffic due to DNS resolver reuse Exploitation status Not known exploited Fix YesAffected product R Reactor Netty Published 08/26/2026 Severity Low CVE-2026-47842Deterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows Ciphertext Correlation Exploitation status Not known exploited Fix YesAffected product S Spring Security Published 08/26/2026 Severity Medium CVE-2026-47834Spring Data JPA Sort expression validation bypass Exploitation status Not known exploited Fix YesAffected product S Spring Data JPA Published 08/26/2026 Severity Medium CVE-2026-47841WebAuthn User Verification Bypass via Session Serialization Exploitation status Not known exploited Fix YesAffected product S Spring Security Published 08/26/2026 Severity High CVE-2026-47837Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Config Published 08/26/2026 Severity Medium CVE-2026-47836Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Config Published 08/26/2026 Severity High CVE-2026-41707Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay Exploitation status Not known exploited Fix YesAffected product S Spring Security Published 08/25/2026 Severity High CVE-2026-59295Micrometer instrumentation of Apache HttpAsyncClient DoS vulnerability Exploitation status Not known exploited Fix YesAffected product M Micrometer Published 08/24/2026 Severity Medium CVE-2026-59318DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via Prompt Injection Exploitation status Not known exploited Fix YesAffected product S Spring AI Published 08/21/2026 Severity Medium CVE-2026-59308Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation Exploitation status Not known exploited Fix Not confirmed Affected product S Spring AI Published 08/21/2026 Severity Medium CVE-2026-59279Unbounded persistent session allocation via repeated initialize requests Exploitation status Not known exploited Fix Not confirmed Affected product S Spring AI Published 08/21/2026 Severity High CVE-2026-59296Micrometer StatsD and Logging meter registries line-protocol and log injection vulnerability Exploitation status Not known exploited Fix YesAffected product M Micrometer Published 08/21/2026 Severity Medium CVE-2026-59323Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability Exploitation status Not known exploited Fix YesAffected product M Micrometer Tracing Published 08/21/2026 Severity Medium CVE-2026-59326HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server Exploitation status Not known exploited Fix YesAffected product S Spring Tools for Eclipse Published 07/30/2026 Severity Low CVE-2026-59328Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips Exploitation status Not known exploited Fix YesAffected product S Spring Tools for Eclipse Published 07/30/2026 Severity Medium CVE-2026-59327Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations Exploitation status Not known exploited Fix YesAffected product S Spring Tools for Eclipse Published 07/30/2026 Severity Medium CVE-2026-47882Spring Boot DevTools remote secret generated with a non-cryptographic PRNG Exploitation status Not known exploited Fix YesAffected product S Spring Tools for Eclipse Published 07/30/2026 Severity High CVE-2026-47873Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces Exploitation status Not known exploited Fix YesAffected product S Spring Tools for Eclipse Published 07/30/2026 Severity High CVE-2026-47858live information startup mode is vulnerable for remote code execution Exploitation status Not known exploited Fix YesAffected product S Spring Tools for Eclipse Published 07/30/2026 Severity High CVE-2026-41862CVE-2026-41862 Exploitation status Not known exploited Fix YesAffected product S Spring Statemachine Published 06/23/2026 Severity High CVE-2026-47825Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situations Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Gateway Published 06/15/2026 Severity High CVE-2026-41708Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability Exploitation status Not known exploited Fix YesAffected product S Spring Cloud Sleuth Published 06/15/2026 Severity High