CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-59324 HIGH

fluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunction

CVSS 8.2 EPSS 0.28% Aug 27, 2026
CVE-2026-59322 MEDIUM

EmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeaders

CVSS 6.3 EPSS 0.29% Aug 27, 2026
CVE-2026-59321 MEDIUM

Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check

CVSS 5.4 EPSS 0.18% Aug 27, 2026
CVE-2026-59320 MEDIUM

In Spring AMQP the link credit never replenished on listener exception path

CVSS 6.5 EPSS 0.42% Aug 27, 2026
CVE-2026-59319 MEDIUM

RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data Exposure

CVSS 4.3 EPSS 0.30% Aug 27, 2026
CVE-2026-59317 MEDIUM

In Spring for Apache Kafka, missing header validation in DeadLetterPublishingRecovererFactory enables denial of service via a poison-pill loop

CVSS 6.5 EPSS 0.42% Aug 27, 2026
CVE-2026-59316 HIGH

Spring Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS)

CVSS 8.2 EPSS 0.32% Aug 27, 2026
CVE-2026-59315 MEDIUM

Spring Cloud Config Monitor Denial of Service

CVSS 5.3 EPSS 0.40% Aug 27, 2026
CVE-2026-59314 LOW

Spring Framework response splitting in ContentDisposition

CVSS 3.7 EPSS 0.26% Aug 27, 2026
CVE-2026-59311 MEDIUM

Fixed predictable /tmp/ziptransformer work directory enables symlink pre-creation

CVSS 6.8 EPSS 0.39% Aug 27, 2026
CVE-2026-59306 LOW

Potential for deserialization of untrusted types in Spring Cloud Stream

CVSS 3.8 EPSS 0.23% Aug 27, 2026
CVE-2026-59313 CRITICAL

Server Sent Event stream corruption in Spring MVC functional web framework

CVSS 9.8 EPSS 0.56% Aug 27, 2026
CVE-2026-59307 HIGH

Deserialization allow-list silently bypassed: setBeanClassLoader replaces deserializer but mapper keeps stale reference

CVSS 8.0 EPSS 0.42% Aug 27, 2026
CVE-2026-59305 LOW

Partition interceptor may be improperly added while sending message

CVSS 3.8 EPSS 0.21% Aug 27, 2026
CVE-2026-59304 LOW

Improper caching of the original content type in Spring Cloud Stream Avro

CVSS 3.8 EPSS 0.21% Aug 27, 2026
CVE-2026-59303 LOW

Dynamic destination cache size is not properly bound in Spring Cloud Stream

CVSS 3.8 EPSS 0.21% Aug 27, 2026
CVE-2026-59302 LOW

Potential for logging sensitive data in Spring Cloud Stream

CVSS 3.1 EPSS 0.17% Aug 27, 2026
CVE-2026-59301 MEDIUM

Potential for logging sensitive data in Spring Cloud Function Azure

CVSS 4.9 EPSS 0.23% Aug 27, 2026
CVE-2026-59300 LOW

Potential for logging sensitive data in Spring Cloud Function AWS

CVSS 3.5 EPSS 0.21% Aug 27, 2026
CVE-2026-59299 LOW

Composition lookup can potentially poison base function in Spring Cloud Function

CVSS 3.5 EPSS 0.21% Aug 27, 2026
CVE-2026-59298 LOW

Potential for improper filtering of HTTP headers in Spring Cloud Function

CVSS 3.5 EPSS 0.22% Aug 27, 2026
CVE-2026-59297 LOW

Spring Cloud Function can incorrectly determine if URI is secure

CVSS 3.5 EPSS 0.13% Aug 27, 2026
CVE-2026-59294 MEDIUM

Arbitrary File Write via Path Traversal in ResourceCacheService

CVSS 6.5 EPSS 0.36% Aug 27, 2026
CVE-2026-59293 MEDIUM

SMB minimum protocol dialect defaults to SMB1

CVSS 6.6 EPSS 0.24% Aug 27, 2026
CVE-2026-59292 LOW

World-readable metadata file in PropertiesPersistingMetadataStore (insecure temp-file permissions)

CVSS 3.2 EPSS 0.15% Aug 27, 2026

Showing 1 to 25 CVEs · page 1 (more available)