Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

7.02025202620272028

Недавние уязвимости Spring Framework

Количество 422

github логотип

GHSA-wg35-8jpf-2xv3

5 месяцев назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-6p4f-wcwh-5vvm

5 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-22745

5 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Denial of Servic ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-22745

5 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-22741

5 месяцев назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2026-22741

5 месяцев назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title  with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2026-22740

5 месяцев назад

A WebFlux server application that processes multipart requests creates ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-22740

5 месяцев назад

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-22741

5 месяцев назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2026-22740

5 месяцев назад

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-wg35-8jpf-2xv3

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

CVSS3: 3.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-6p4f-wcwh-5vvm

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources

CVSS3: 5.3
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-22745

Spring MVC and WebFlux applications are vulnerable to Denial of Servic ...

CVSS3: 5.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-22745

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-22741

Spring MVC and WebFlux applications are vulnerable to cache poisoning ...

CVSS3: 3.1
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-22741

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title  with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

CVSS3: 3.1
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-22740

A WebFlux server application that processes multipart requests creates ...

CVSS3: 6.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-22740

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-22741

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

CVSS3: 3.1
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-22740

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

CVSS3: 6.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу


Поделиться