CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
fluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunction
EmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeaders
Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check
In Spring AMQP the link credit never replenished on listener exception path
RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data Exposure
In Spring for Apache Kafka, missing header validation in DeadLetterPublishingRecovererFactory enables denial of service via a poison-pill loop
Spring Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS)
Spring Cloud Config Monitor Denial of Service
Spring Framework response splitting in ContentDisposition
Fixed predictable /tmp/ziptransformer work directory enables symlink pre-creation
Potential for deserialization of untrusted types in Spring Cloud Stream
Server Sent Event stream corruption in Spring MVC functional web framework
Deserialization allow-list silently bypassed: setBeanClassLoader replaces deserializer but mapper keeps stale reference
Partition interceptor may be improperly added while sending message
Improper caching of the original content type in Spring Cloud Stream Avro
Dynamic destination cache size is not properly bound in Spring Cloud Stream
Potential for logging sensitive data in Spring Cloud Stream
Potential for logging sensitive data in Spring Cloud Function Azure
Potential for logging sensitive data in Spring Cloud Function AWS
Composition lookup can potentially poison base function in Spring Cloud Function
Potential for improper filtering of HTTP headers in Spring Cloud Function
Spring Cloud Function can incorrectly determine if URI is secure
Arbitrary File Write via Path Traversal in ResourceCacheService
SMB minimum protocol dialect defaults to SMB1
World-readable metadata file in PropertiesPersistingMetadataStore (insecure temp-file permissions)
Showing 1 to 25 CVEs · page 1 (more available)