VMware / Spring Framework
86 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59314 | Spring Framework response splitting in ContentDisposition | LOW | 3.7 | Aug 27, 2026 |
| CVE-2026-59313 | Server Sent Event stream corruption in Spring MVC functional web framework | CRITICAL | 9.8 | Aug 27, 2026 |
| CVE-2026-59283 | Spring Framework Safety Guard Bypass via SpEL Expression Compilation | CRITICAL | 9.8 | Aug 27, 2026 |
| CVE-2026-59282 | Spring Framework Denial of Service via Unbounded List Growth in Data Binding | HIGH | 7.5 | Aug 27, 2026 |
| CVE-2026-59281 | Spring Framework Cross-site Scripting via EscapedErrors | MEDIUM | 6.1 | Aug 27, 2026 |
| CVE-2026-59280 | Spring Framework Path Traversal via Backslash in SpringTemplateLoader | MEDIUM | 4.3 | Aug 27, 2026 |
| CVE-2026-47893 | Spring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketService | HIGH | 7.5 | Aug 27, 2026 |
| CVE-2026-47892 | Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints | CRITICAL | 9.8 | Aug 27, 2026 |
| CVE-2026-47891 | Spring Framework maxInMemorySize Bypassed in Jaxb2Decoder | CRITICAL | 9.8 | Aug 27, 2026 |
| CVE-2026-47890 | Spring Framework Server Sent Event stream corruption while rendering fragments | CRITICAL | 9.8 | Aug 27, 2026 |
| CVE-2026-47889 | Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse | HIGH | 7.5 | Aug 27, 2026 |
| CVE-2026-47888 | Spring Framework Memory Leak via SETUP Frame in RSocketMessageHandler | HIGH | 7.5 | Aug 27, 2026 |
| CVE-2026-47887 | Spring Framework Open Redirect in UrlFileNameViewController | MEDIUM | 6.1 | Aug 27, 2026 |
| CVE-2026-47886 | Spring Framework Denial of Service via Unbounded Exponentiation in SpEL Expressions | HIGH | 7.5 | Aug 27, 2026 |
| CVE-2026-47885 | Spring Framework maxPartSize Ignored in PartEventHttpMessageReader | HIGH | 7.5 | Aug 27, 2026 |
| CVE-2026-47884 | Spring Framework Improper Path Limitation in XsltView | CRITICAL | 9.8 | Aug 27, 2026 |
| CVE-2026-47883 | Spring Framework Open Redirect in UrlHandlerFilter | MEDIUM | 6.1 | Aug 27, 2026 |
| CVE-2026-41855 | Spring Framework Unsafe Deserialization via Jackson JMS Converters | CRITICAL | 9.8 | Jun 9, 2026 |
| CVE-2026-41854 | Spring Framework Server-Side Request Forgery via UriComponentsBuilder | MEDIUM | 6.5 | Jun 9, 2026 |
| CVE-2026-41853 | Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux | MEDIUM | 5.3 | Jun 9, 2026 |
| CVE-2026-41852 | Spring Framework Arbitrary Method Invocation in SpEL Expressions | MEDIUM | 5.3 | Jun 9, 2026 |
| CVE-2026-41851 | Spring Framework Denial of Service via Unbounded Cache in SpEL | HIGH | 7.5 | Jun 9, 2026 |
| CVE-2026-41850 | Spring Framework Algorithmic Denial of Service via SpEL Expressions | HIGH | 7.5 | Jun 9, 2026 |
| CVE-2026-41849 | Spring Framework Denial of Service via Integer Overflow in SpEL Expressions | HIGH | 7.5 | Jun 9, 2026 |
| CVE-2026-41848 | Spring Framework Denial of Service via AntPathMatcher | HIGH | 7.5 | Jun 9, 2026 |
Showing 1 to 25 of 86 CVEs