VMware VMware

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any VMware product.

RSS Feeds for VMware security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in VMware products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by VMware Sorted by Most Security Vulnerabilities since 2018

VMware Spring Framework229 vulnerabilities

VMware Cloud Foundation128 vulnerabilities

VMware Workstation111 vulnerabilities

VMware ESXi94 vulnerabilities
VMware ESXi is a type-1 bare metal hypervisor.

VMware Fusion65 vulnerabilities

VMware Vcenter Server64 vulnerabilities

VMware Esx29 vulnerabilities

VMware Spring Security27 vulnerabilities

VMware Aria Operations22 vulnerabilities

VMware Telco Cloud Platform21 vulnerabilities

VMware Rabbitmq15 vulnerabilities

VMware Vrealize Operations14 vulnerabilities

VMware Tools9 vulnerabilities

VMware Vrealize Automation8 vulnerabilities

VMware Server7 vulnerabilities

VMware Airwatch Console6 vulnerabilities

VMware Horizon Client6 vulnerabilities

VMware Spring Cloud Gateway6 vulnerabilities

VMware Player5 vulnerabilities

VMware Aria Automation4 vulnerabilities

VMware Horizon Daas4 vulnerabilities

VMware Identity Manager3 vulnerabilities

VMware Pinniped3 vulnerabilities

VMware Remote Console3 vulnerabilities

VMware Vma3 vulnerabilities

VMware Ace2 vulnerabilities

VMware Cloud Director2 vulnerabilities

VMware Nsx2 vulnerabilities

VMware Rabbitmq Java Client2 vulnerabilities

Vmware Hcx2 vulnerabilities

VMware Sd Wan Edge1 vulnerability

Recent VMware Security Advisories

Advisory Title Published
2026-08-20 cve-2026-47859 - MEDIUM - Unbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoS August 20, 2026
2026-08-20 cve-2026-47837 - MEDIUM - Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests August 20, 2026
2026-08-20 cve-2026-59281 - MEDIUM - Spring Framework Cross-site Scripting via EscapedErrors August 20, 2026
2026-08-20 cve-2026-47861 - MEDIUM - UDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when acknowledge=false August 20, 2026
2026-08-20 cve-2026-47856 - MEDIUM - JsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-list August 20, 2026
2026-08-20 cve-2026-47860 - MEDIUM - Unbounded decompression of attacker-supplied compressed message bodies August 20, 2026
2026-08-20 cve-2026-47875 - MEDIUM - JobParameterDeserializer bypasses the trusted-type allowlist August 20, 2026
2026-08-20 cve-2026-41707 - HIGH - Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay August 20, 2026
2026-08-20 cve-2026-47841 - HIGH - WebAuthn User Verification Bypass via Session Serialization August 20, 2026
2026-08-20 cve-2026-47836 - HIGH - Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN August 20, 2026

Known Exploited VMware Vulnerabilities

The following VMware vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
VMware ESXi and Workstation TOCTOU Race Condition Vulnerability VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.
CVE-2025-22224 Exploit Probability: 1.6%
March 4, 2025
VMware ESXi Arbitrary Write Vulnerability VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.
CVE-2025-22225 Exploit Probability: 1.0%
March 4, 2025
VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.
CVE-2025-22226 Exploit Probability: 1.7%
March 4, 2025
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.
CVE-2024-38812 Exploit Probability: 54.6%
November 20, 2024
VMware vCenter Server Privilege Escalation Vulnerability VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.
CVE-2024-38813 Exploit Probability: 17.4%
November 20, 2024
VMware ESXi Authentication Bypass Vulnerability VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.
CVE-2024-37085 Exploit Probability: 26.0%
July 30, 2024
VMware vCenter Server Incorrect Default File Permissions Vulnerability VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.
CVE-2022-22948 Exploit Probability: 13.3%
July 17, 2024
VMware vCenter Server Out-of-Bounds Write Vulnerability VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.
CVE-2023-34048 Exploit Probability: 99.4%
January 22, 2024
VMware Tools Authentication Bypass Vulnerability VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.
CVE-2023-20867 Exploit Probability: 13.5%
June 23, 2023
Vmware Aria Operations for Networks Command Injection Vulnerability VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.
CVE-2023-20887 Exploit Probability: 98.3%
June 22, 2023
VMware Spring Cloud Gateway Code Injection Vulnerability Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
CVE-2022-22947 Exploit Probability: 98.3%
May 16, 2022
VMware Multiple Products Privilege Escalation Vulnerability VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
CVE-2022-22960 Exploit Probability: 35.8%
April 15, 2022
VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
CVE-2022-22954 Exploit Probability: 100.0%
April 14, 2022
Spring Framework JDK 9+ Remote Code Execution Vulnerability Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CVE-2022-22965 Exploit Probability: 99.6%
April 4, 2022
VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.
CVE-2018-6961 Exploit Probability: 86.3%
March 25, 2022
VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.
CVE-2021-21973 Exploit Probability: 87.6%
March 7, 2022
VMware Server Side Request Forgery in vRealize Operations Manager API Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
CVE-2021-21975 Exploit Probability: 78.3%
January 18, 2022
VMware vCenter Server Improper Access Control Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
CVE-2021-22017 Exploit Probability: 49.2%
January 10, 2022
VMware ESXi/Horizon DaaS Appliances Heap-Overwrite Vulnerability OpenSLP as used in ESXi and the Horizon DaaS appliances have a heap overwrite issue. A malicious actor with network access to port 427 on an ESXi host or on any Horizon DaaS management appliance may be able to overwrite the heap of the OpenSLP service resulting in remote code execution.
CVE-2019-5544 Exploit Probability: 97.3%
November 3, 2021
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector Comm VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
CVE-2020-4006 Exploit Probability: 17.3%
November 3, 2021

Of the known exploited vulnerabilities above, 9 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 8 known exploited VMware vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

Top 10 Riskiest VMware Vulnerabilities

Based on the current exploit probability, these VMware vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.

Rank CVE EPSS Vulnerability
1 CVE-2021-21985 100.0% VMware vCenter Server Remote Code Execution Vulnerability
2 CVE-2021-22005 100.0% VMware vCenter Server File Upload
3 CVE-2022-22954 100.0% VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability
4 CVE-2021-21972 99.9% VMware vCenter Server Remote Code Execution Vulnerability
5 CVE-2022-22965 99.6% Spring Framework JDK 9+ Remote Code Execution Vulnerability
6 CVE-2023-34048 99.4% VMware vCenter Server Out-of-Bounds Write Vulnerability
7 CVE-2023-20887 98.3% Vmware Aria Operations for Networks Command Injection Vulnerability
8 CVE-2022-22947 98.3% VMware Spring Cloud Gateway Code Injection Vulnerability
9 CVE-2019-5544 97.3% VMware ESXi/Horizon DaaS Appliances Heap-Overwrite Vulnerability
10 CVE-2020-3952 90.4% VMware vCenter Server Info Disclosure Vulnerability

By the Year

In 2026 there have been 208 vulnerabilities in VMware with an average score of 6.7 out of ten. Last year, in 2025 VMware had 40 security vulnerabilities published. That is, 168 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.47




Year Vulnerabilities Average Score
2026 208 6.68
2025 40 7.15
2024 52 7.05
2023 72 7.31
2022 79 7.21
2021 77 7.30
2020 61 7.01
2019 31 7.15
2018 59 7.22

It may take a day or so for new VMware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent VMware Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-59293 Aug 27, 2026
Spring Integration SMB1 Downgrade via jCIFS Client (v6.4-7.1) Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Spring Framework
CVE-2026-59292 Aug 27, 2026
Spring Integration world-readable temp metadata file (ConcurrentMetadataStore) PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Spring Framework
CVE-2026-59289 Aug 27, 2026
Spring GraphQL Paged Query DOS (v1.2-2.0) Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.2.0 - 1.3.9
Spring Framework
CVE-2026-59288 Aug 27, 2026
Spring for GraphQL 1.0-2.0.4 GraphiQL XSS/Info Leak via Malicious URL The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
Spring Framework
CVE-2026-59287 Aug 27, 2026
Spring for GraphQL WebSocket DoS via keepAlive (v1.31.42.0) Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.3.0 - 1.3.9
Spring Framework
CVE-2026-59286 Aug 27, 2026
Spring for GraphQL 1.0-2.0.4 GraphiQL SRI missing - XSS risk The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
Spring Framework
CVE-2026-59285 Aug 27, 2026
Unsafe Deserialization in spring-for-graphql 2.0.0-2.0.4 Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4
Spring Framework
CVE-2026-59284 Aug 27, 2026
Spring Cloud Commons 5.0.x: Unrestricted /actuator/env Property Injection There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commons 5.0.0 - 5.0.2 Spring Cloud Commons 4.3.0 - 4.3.3 Spring Cloud Commons 4.0.0 - 4.2.6 Spring Cloud Commons 3.1.10 and earlier
Spring Framework
CVE-2026-59283 Aug 27, 2026
Spring Framework SpEL Safety Guard Bypass 5.2.25+ 7.0.8 Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Spring Framework
CVE-2026-59282 Aug 27, 2026
Spring Framework 57 DoS via Property Path Binding (<=7.0.8) Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Spring Framework
CVE-2026-59281 Aug 27, 2026
Spring Framework 57 Reflected XSS via Errors.getFieldError() Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors are vulnerable to arbitrary HTML/JavaScript code injection, potentially resulting in a reflected cross-site scripting (XSS) vulnerability. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Spring Framework
CVE-2026-59277 Aug 27, 2026
IP Classification Flaw in Spring Security 7.1.0 InetAddressMatcher Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or external (public) network. Spring Security 7.1.0
Spring Framework
CVE-2026-59276 Aug 27, 2026
Spring Security Timing Attack: String.equals() non-constant comparison v67 Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject an incorrect value is proportional to the number of leading characters that match the expected value. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25
Spring Framework
CVE-2026-59280 Aug 27, 2026
Spring Framework FreeMarker Path Traversal via Untrusted View Name (Fixed 7.0.9+) Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Spring Framework
CVE-2026-59272 Aug 27, 2026
Spring AMQP Log4j2 TLS MITM (2.4.18- & 3.2.03.2.12 & 4.0.04.0.4) Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Spring Framework
CVE-2026-59355 Aug 27, 2026
Spring Authorization Server 1.5.0-1.5.7 Open Redirect via request_uri In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site.
Server
CVE-2026-47893 Aug 27, 2026
Spring Framework 5.2-7.0 WS Header Leak (CVE-202647893) A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Spring Framework
CVE-2026-47892 Aug 27, 2026
Spring Framework 5-7 WebFlux Header Predicate Bypass (CVE-2026-47892) A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE
Spring Framework
CVE-2026-47891 Aug 27, 2026
Spring Framework WebFlux XML reader (Aalto) MaxInMemorySize limit bypass (5.2-7.0) A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Spring Framework
CVE-2026-47890 Aug 27, 2026
Spring Framework SSE Stream Corruption 6.2.0-6.2.19, 7.0.0-7.0.8 Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Spring Framework
CVE-2026-47889 Aug 27, 2026
Spring Framework WebFlux SameSite Cookies Missing (6.2.0-6.2.19, 7.0.0-7.0.8) A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Spring Framework
CVE-2026-47888 Aug 27, 2026
Spring Framework 5.2-7 RSocket memory leak via malformed SETUP frame A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE
Spring Framework
CVE-2026-47887 Aug 27, 2026
Spring Framework <7.0.8 Open Redirect via UrlFileNameViewController A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Spring Framework
CVE-2026-47886 Aug 27, 2026
Spring Framework DoS via SpEL Power Operator ^ (BigDecimal) 5.3-5.3.49 Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Spring Framework
CVE-2026-47885 Aug 27, 2026
Spring Framework 6.x-7.x Unenforced PartSize in PartEventHttpMessageReader The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28
Spring Framework
CVE-2026-47884 Aug 27, 2026
Spring Framework SSRF/RCE via XsltView in 5.2.25+ to 7.0.8 Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Spring Framework
CVE-2026-47883 Aug 27, 2026
Spring Framework UrlHandlerFilter Open Redirect (6.2.0-6.2.19, 7.0.0-7.0.8) UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Spring Framework
CVE-2026-59278 Aug 27, 2026
Spring Kafka 4.x JsonKafkaHeaderMapper allows java.net deserialization JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used which is the default configuration for all @KafkaListener consumers an external Kafka producer can inject a java.net.InetAddress type via the spring_json_header_types message header. Spring for Apache Kafka 4.1.0 Spring for Apache Kafka 4.0.0 - 4.0.6 Spring for Apache Kafka 3.0.0 - 3.3.16 Spring for Apache Kafka 2.9.0 - 2.9.14 Spring for Apache Kafka 2.8.12 and earlier
Spring Framework
CVE-2026-59275 Aug 27, 2026
Spring AMQP 4.1.0+ Vulnerability: System.exit Crash via AMQP Message A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Spring Framework
CVE-2026-59274 Aug 27, 2026
Spring Integration UnZipTransformer DOS via ZIP bomb pre-7.1.0 The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Spring Framework
CVE-2026-59271 Aug 27, 2026
Spring AMQP <=4.1.0 Admin PW Logged in Exception (Cleartext) When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Spring Framework
CVE-2026-59270 Aug 27, 2026
Spring Security UnboundID LDAP auto-admin cred & all-interfaces bind (v5.7-7.1) Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25
Spring Framework
CVE-2026-47894 Aug 27, 2026
Spring Cloud Config Server 5.0.0-5.0.4: Native Env Repo Exposes Config Files Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
Spring Framework
CVE-2026-47881 Aug 27, 2026
Spring Batch 4-6.0.x FlatFileItemReader Multi-line Record DoS Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines for example, a CSV field that contains embedded newlines wrapped in quotes. A specially crafted input file could exploit the way the reader assembles those multi-line records to consume excessive CPU time and memory, causing the batch job to stall or run out of memory. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.0 - 5.2.6 Spring Batch 4.3.0 - 4.3.13
Spring Framework
CVE-2026-47880 Aug 27, 2026
Spring Integration <7.1 JMS Header Injection via replyChannel Property A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integration MessageHeaders. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Spring Framework
CVE-2026-47879 Aug 27, 2026
Spring Cloud Gateway <=5.0.2 JsonToGrpcGWFF arbitrary resource location Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier
Spring Framework
CVE-2026-47877 Aug 27, 2026
Spring Security Auth Server XSS via unencoded consent page (7.0.07.0.6) Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6
Spring Framework
CVE-2026-47878 Aug 27, 2026
Spring Batch 5.x-6.0.4 Deserialization via DefaultExecutionContextSerializer DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowlist. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.6 and earlier
Spring Framework
CVE-2026-47875 Aug 27, 2026
Spring Batch 5.2-6.0.4: Jackson RCE via Untrusted Deserialization Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enforce the trusted-types allowlist, allowing an attacker to craft malicious input that can lead to arbitrary code execution, including known Jackson RCE gadgets. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.0 - 5.2.6
Spring Framework
CVE-2026-47864 Aug 27, 2026
Spring Integration: Unsafe deserialization in SerializingHttpMessageConverter (<7.1.0) SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serializable type is read directly via readObject(). If an application using this converter on an inbound HTTP endpoint has any known Java deserialization "gadget" on its classpath, a remote, unauthenticated attacker can achieve arbitrary code execution. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Spring Framework
CVE-2026-47849 Aug 27, 2026
Spring Data REST 3-5 vulnerable: @Id/@Version mutable via JSON Patch Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier
Spring Framework
CVE-2026-47874 Aug 26, 2026
Reactor Netty 1.1-1.3 HTTP/1.1 Pipelining Memory Exhaustion The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Spring Framework
CVE-2026-47861 Aug 26, 2026
Unauthenticated Remote UDP Injection via Spring Integration UDP Inbound Adapter 5.5.21-7.1.0 An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Spring Framework
CVE-2026-47863 Aug 26, 2026
Reactor Core 3.8.x bufferTimeout DoS (fairBackpressure) In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier
Spring Framework
CVE-2026-47862 Aug 26, 2026
Spring Integration 6.4-7.1.0 ZipTransformer Path Traversal via file_name Header An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Spring Framework
CVE-2026-47860 Aug 26, 2026
Spring AMQP 4.1.0 JVM Crash via Message Decompression (CVE-2026-47860) An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Spring Framework
CVE-2026-47859 Aug 26, 2026
Spring Integration 7.1.0+ RFC6587SyslogDeserializer Byte Array CVE-2026-47859 RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size with no upper bound. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Spring Framework
CVE-2026-47857 Aug 26, 2026
Reactor Core DoS via Flux.windowTimeout fairBackpressure (3.8.6) In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier
Spring Framework
CVE-2026-47856 Aug 26, 2026
Spring Integration 6.5.x-7.1 JSON Deser via json_TypeId__ Header (No Whitelist) Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Spring Framework
CVE-2026-47852 Aug 26, 2026
Spring AI Local Path Traversal in ONNX Model Loading (1.01.0.9,1.1.01.1.8,2.0.0) A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
Spring Framework
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.