Spring Framework — универсальный фреймворк с открытым исходным кодом для Java-платформы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 349
CVE-2026-41854
Due to incorrect host parsing, applications that rely on UriComponents ...
CVE-2026-41854
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
CVE-2026-41853
Spring MVC and WebFlux applications are vulnerable to Multipart reques ...
CVE-2026-41853
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
CVE-2026-41852
A vulnerability in Spring Expression Language (SpEL) evaluation logic ...
CVE-2026-41852
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
CVE-2026-41851
Applications which accept user-supplied Spring Expression Language (Sp ...
CVE-2026-41851
Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
CVE-2026-41850
Applications that evaluate user-supplied Spring Expression Language (S ...
CVE-2026-41850
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2026-41854 Due to incorrect host parsing, applications that rely on UriComponents ... | CVSS3: 4.2 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-41854 Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18. | CVSS3: 4.2 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-41853 Spring MVC and WebFlux applications are vulnerable to Multipart reques ... | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-41853 Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-41852 A vulnerability in Spring Expression Language (SpEL) evaluation logic ... | CVSS3: 3.7 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-41852 A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 3.7 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-41851 Applications which accept user-supplied Spring Expression Language (Sp ... | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-41851 Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-41850 Applications that evaluate user-supplied Spring Expression Language (S ... | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-41850 Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу