Spring VMware Spring

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in VMware Spring.

Recent VMware Spring Security Advisories

Advisory Title Published
2026-08-20 cve-2026-47887 - MEDIUM - Spring Framework Open Redirect in UrlFileNameViewController August 20, 2026
2026-08-20 cve-2026-41707 - HIGH - Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay August 20, 2026
2026-08-20 cve-2026-47837 - MEDIUM - Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests August 20, 2026
2026-08-20 cve-2026-47881 - MEDIUM - Denial of Service in Spring Batch FlatFileItemReader via Malformed Input File August 20, 2026
2026-08-20 cve-2026-47879 - HIGH - Spring Cloud Gateway SSRF and native file access with gRPC August 20, 2026
2026-08-20 cve-2026-47877 - HIGH - Spring Security Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS) August 20, 2026
2026-08-20 cve-2026-47885 - MEDIUM - Spring Framework maxPartSize Ignored in PartEventHttpMessageReader August 20, 2026
2026-08-20 cve-2026-47842 - MEDIUM - Deterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows Ciphertext Correlation August 20, 2026
2026-08-20 cve-2026-47888 - MEDIUM - Spring Framework Memory Leak via SETUP Frame in RSocketMessageHandler August 20, 2026
2026-08-20 cve-2026-59281 - MEDIUM - Spring Framework Cross-site Scripting via EscapedErrors August 20, 2026

By the Year

In 2026 there have been 0 vulnerabilities in VMware Spring. Spring did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 0 0.00
2023 1 7.80

It may take a day or so for new Spring vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent VMware Spring Security Vulnerabilities

Deserialization Attack via Header in Spring-Kafka 3.0.9 (checkDeserExWhen...)
CVE-2023-34040 7.8 - High - August 24, 2023

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: * The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record * The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container properties to true. * The user allows untrusted sources to publish to a Kafka topic By default, these properties are false, and the container only attempts to deserialize the headers if an ErrorHandlingDeserializer is configured. The ErrorHandlingDeserializer prevents the vulnerability by removing any such malicious headers before processing the record.

Marshaling, Unmarshaling

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for VMware Spring or by VMware? Click the Watch button to subscribe.

VMware
Vendor

VMware Spring
Product

subscribe