Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

7.02025202620272028

Недавние уязвимости Spring Framework

Количество 348

debian логотип

CVE-2026-41849

около 2 месяцев назад

An integer overflow vulnerability exists in the evaluation logic of th ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-41849

около 2 месяцев назад

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-41848

около 2 месяцев назад

Applications may be vulnerable to a Regular Expression Denial of Servi ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2026-41848

около 2 месяцев назад

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path). Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2026-41847

около 2 месяцев назад

Spring WebFlux applications may be vulnerable to a security bypass whe ...

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2026-41847

около 2 месяцев назад

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2026-41846

около 2 месяцев назад

Spring MVC applications which accept user-supplied values in the cssCl ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-41846

около 2 месяцев назад

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-41845

около 2 месяцев назад

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape ...

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-41845

около 2 месяцев назад

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2026-41849

An integer overflow vulnerability exists in the evaluation logic of th ...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-41849

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-41848

Applications may be vulnerable to a Regular Expression Denial of Servi ...

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-41848

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path). Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-41847

Spring WebFlux applications may be vulnerable to a security bypass whe ...

CVSS3: 4.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-41847

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 4.8
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-41846

Spring MVC applications which accept user-supplied values in the cssCl ...

CVSS3: 5.9
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-41846

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-41845

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape ...

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-41845

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу


Поделиться