Spring / Spring Tools for Eclipse
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59326 | HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server | LOW | 3.3 | Jul 30, 2026 |
| CVE-2026-59328 | Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips | MEDIUM | 4.2 | Jul 30, 2026 |
| CVE-2026-59327 | Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations | MEDIUM | 4.4 | Jul 30, 2026 |
| CVE-2026-47882 | Spring Boot DevTools remote secret generated with a non-cryptographic PRNG | HIGH | 8.3 | Jul 30, 2026 |
| CVE-2026-47873 | Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces | HIGH | 8.0 | Jul 30, 2026 |
| CVE-2026-47858 | live information startup mode is vulnerable for remote code execution | HIGH | 8.0 | Jul 30, 2026 |
Showing 1 to 6 of 6 CVEs