VMware Spring Framework
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in VMware Spring Framework.
Recent VMware Spring Framework Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 2026-08-20 | cve-2026-47836 - HIGH - Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN | August 20, 2026 |
| 2026-08-20 | cve-2026-47837 - MEDIUM - Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests | August 20, 2026 |
| 2026-08-20 | cve-2026-47856 - MEDIUM - JsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-list | August 20, 2026 |
| 2026-08-20 | cve-2026-59281 - MEDIUM - Spring Framework Cross-site Scripting via EscapedErrors | August 20, 2026 |
| 2026-08-20 | cve-2026-47860 - MEDIUM - Unbounded decompression of attacker-supplied compressed message bodies | August 20, 2026 |
| 2026-08-20 | cve-2026-47859 - MEDIUM - Unbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoS | August 20, 2026 |
| 2026-08-20 | cve-2026-47842 - MEDIUM - Deterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows Ciphertext Correlation | August 20, 2026 |
| 2026-08-20 | cve-2026-47875 - MEDIUM - JobParameterDeserializer bypasses the trusted-type allowlist | August 20, 2026 |
| 2026-08-20 | cve-2026-47861 - MEDIUM - UDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when acknowledge=false | August 20, 2026 |
| 2026-08-20 | cve-2026-41707 - HIGH - Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay | August 20, 2026 |
EOL Dates
Ensure that you are using a supported version of VMware Spring Framework. Here are some end of life, and end of support dates for VMware Spring Framework.
| Release | EOL Date | End of Extended Support | Status |
|---|---|---|---|
| 7.0 | July 31, 2027 | July 31, 2028 |
Active
VMware Spring Framework 7.0 will become EOL next year, in July 2027. |
| 6.2 | June 30, 2026 | June 30, 2032 |
EOL
VMware Spring Framework 6.2 became EOL in 2026 and the extended support period ends in 2032. |
| 6.1 | June 30, 2025 | June 30, 2032 |
EOL
VMware Spring Framework 6.1 became EOL in 2025 and the extended support period ends in 2032. |
| 6.0 | June 30, 2024 | June 30, 2032 |
EOL
VMware Spring Framework 6.0 became EOL in 2024 and the extended support period ends in 2032. |
| 5.3 | August 31, 2024 | June 30, 2029 |
EOL
VMware Spring Framework 5.3 became EOL in 2024 and the extended support period ends in 2029. |
| 5.2 | December 31, 2021 | June 30, 2029 |
EOL
VMware Spring Framework 5.2 became EOL in 2021 and the extended support period ends in 2029. |
| 5.1 | December 31, 2020 | December 31, 2022 |
EOL
VMware Spring Framework 5.1 became EOL in 2020 and the extended support period ended in 2022. |
| 5.0 | December 31, 2020 | - |
EOL
VMware Spring Framework 5.0 became EOL in 2020. |
| 4.3 | December 31, 2020 | - |
EOL
VMware Spring Framework 4.3 became EOL in 2020. |
| 3.2 | December 31, 2016 | - |
EOL
VMware Spring Framework 3.2 became EOL in 2016. |
Extended Support differs by vendor, and may cost additional fees. Check with VMware to see how they define extended support.
By the Year
In 2026 there have been 178 vulnerabilities in VMware Spring Framework with an average score of 6.6 out of ten. Last year, in 2025 Spring Framework had 6 security vulnerabilities published. That is, 172 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.29.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 178 | 6.59 |
| 2025 | 6 | 6.30 |
| 2024 | 6 | 6.40 |
| 2023 | 4 | 7.00 |
| 2022 | 6 | 6.28 |
| 2021 | 2 | 6.05 |
| 2020 | 4 | 7.28 |
| 2019 | 0 | 0.00 |
| 2018 | 11 | 7.61 |
It may take a day or so for new Spring Framework vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent VMware Spring Framework Security Vulnerabilities
Spring Integration SMB1 Downgrade via jCIFS Client (v6.4-7.1)
CVE-2026-59293
6.6 - Medium
- August 27, 2026
Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Algorithm Downgrade
Spring Integration world-readable temp metadata file (ConcurrentMetadataStore)
CVE-2026-59292
3.2 - Low
- August 27, 2026
PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Incorrect Permission Assignment for Critical Resource
Spring GraphQL Paged Query DOS (v1.2-2.0)
CVE-2026-59289
- August 27, 2026
Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.2.0 - 1.3.9
Spring for GraphQL 1.0-2.0.4 GraphiQL XSS/Info Leak via Malicious URL
CVE-2026-59288
- August 27, 2026
The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
Spring for GraphQL WebSocket DoS via keepAlive (v1.31.42.0)
CVE-2026-59287
- August 27, 2026
Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.3.0 - 1.3.9
Spring for GraphQL 1.0-2.0.4 GraphiQL SRI missing - XSS risk
CVE-2026-59286
- August 27, 2026
The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
Unsafe Deserialization in spring-for-graphql 2.0.0-2.0.4
CVE-2026-59285
- August 27, 2026
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4
Spring Cloud Commons 5.0.x: Unrestricted /actuator/env Property Injection
CVE-2026-59284
6.6 - Medium
- August 27, 2026
There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commons 5.0.0 - 5.0.2 Spring Cloud Commons 4.3.0 - 4.3.3 Spring Cloud Commons 4.0.0 - 4.2.6 Spring Cloud Commons 3.1.10 and earlier
Mass Assignment
Spring Framework SpEL Safety Guard Bypass 5.2.25+ 7.0.8
CVE-2026-59283
9.1 - Critical
- August 27, 2026
Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Improper Control of Dynamically-Managed Code Resources
Spring Framework 57 DoS via Property Path Binding (<=7.0.8)
CVE-2026-59282
7.5 - High
- August 27, 2026
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Resource Exhaustion
Spring Framework 57 Reflected XSS via Errors.getFieldError()
CVE-2026-59281
6.1 - Medium
- August 27, 2026
Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors are vulnerable to arbitrary HTML/JavaScript code injection, potentially resulting in a reflected cross-site scripting (XSS) vulnerability. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
XSS
IP Classification Flaw in Spring Security 7.1.0 InetAddressMatcher
CVE-2026-59277
3.7 - Low
- August 27, 2026
Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or external (public) network. Spring Security 7.1.0
Protection Mechanism Failure
Spring Security Timing Attack: String.equals() non-constant comparison v67
CVE-2026-59276
5.9 - Medium
- August 27, 2026
Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject an incorrect value is proportional to the number of leading characters that match the expected value. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25
Observable Timing Discrepancy
Spring Framework FreeMarker Path Traversal via Untrusted View Name (Fixed 7.0.9+)
CVE-2026-59280
4.3 - Medium
- August 27, 2026
Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Directory traversal
Spring AMQP Log4j2 TLS MITM (2.4.18- & 3.2.03.2.12 & 4.0.04.0.4)
CVE-2026-59272
6.8 - Medium
- August 27, 2026
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Improper Validation of Certificate with Host Mismatch
Spring Framework 5.2-7.0 WS Header Leak (CVE-202647893)
CVE-2026-47893
7.5 - High
- August 27, 2026
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Generation of Error Message Containing Sensitive Information
Spring Framework 5-7 WebFlux Header Predicate Bypass (CVE-2026-47892)
CVE-2026-47892
9.8 - Critical
- August 27, 2026
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE
AuthZ
Spring Framework WebFlux XML reader (Aalto) MaxInMemorySize limit bypass (5.2-7.0)
CVE-2026-47891
9.8 - Critical
- August 27, 2026
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Allocation of Resources Without Limits or Throttling
Spring Framework SSE Stream Corruption 6.2.0-6.2.19, 7.0.0-7.0.8
CVE-2026-47890
9.8 - Critical
- August 27, 2026
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
CRLF Injection
Spring Framework WebFlux SameSite Cookies Missing (6.2.0-6.2.19, 7.0.0-7.0.8)
CVE-2026-47889
7.5 - High
- August 27, 2026
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Sensitive Cookie with Improper SameSite Attribute
Spring Framework 5.2-7 RSocket memory leak via malformed SETUP frame
CVE-2026-47888
7.5 - High
- August 27, 2026
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE
Memory Leak
Spring Framework <7.0.8 Open Redirect via UrlFileNameViewController
CVE-2026-47887
6.1 - Medium
- August 27, 2026
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Open Redirect
Spring Framework DoS via SpEL Power Operator ^ (BigDecimal) 5.3-5.3.49
CVE-2026-47886
7.5 - High
- August 27, 2026
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Resource Exhaustion
Spring Framework 6.x-7.x Unenforced PartSize in PartEventHttpMessageReader
CVE-2026-47885
7.5 - High
- August 27, 2026
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28
Allocation of Resources Without Limits or Throttling
Spring Framework SSRF/RCE via XsltView in 5.2.25+ to 7.0.8
CVE-2026-47884
9.8 - Critical
- August 27, 2026
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Directory traversal
Spring Framework UrlHandlerFilter Open Redirect (6.2.0-6.2.19, 7.0.0-7.0.8)
CVE-2026-47883
6.1 - Medium
- August 27, 2026
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Open Redirect
Spring Kafka 4.x JsonKafkaHeaderMapper allows java.net deserialization
CVE-2026-59278
6.5 - Medium
- August 27, 2026
JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used which is the default configuration for all @KafkaListener consumers an external Kafka producer can inject a java.net.InetAddress type via the spring_json_header_types message header. Spring for Apache Kafka 4.1.0 Spring for Apache Kafka 4.0.0 - 4.0.6 Spring for Apache Kafka 3.0.0 - 3.3.16 Spring for Apache Kafka 2.9.0 - 2.9.14 Spring for Apache Kafka 2.8.12 and earlier
SSRF
Spring AMQP 4.1.0+ Vulnerability: System.exit Crash via AMQP Message
CVE-2026-59275
6.6 - Medium
- August 27, 2026
A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Marshaling, Unmarshaling
Spring Integration UnZipTransformer DOS via ZIP bomb pre-7.1.0
CVE-2026-59274
6.5 - Medium
- August 27, 2026
The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Data Amplification
Spring AMQP <=4.1.0 Admin PW Logged in Exception (Cleartext)
CVE-2026-59271
5.3 - Medium
- August 27, 2026
When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Generation of Error Message Containing Sensitive Information
Spring Security UnboundID LDAP auto-admin cred & all-interfaces bind (v5.7-7.1)
CVE-2026-59270
9.4 - Critical
- August 27, 2026
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25
Spring Cloud Config Server 5.0.0-5.0.4: Native Env Repo Exposes Config Files
CVE-2026-47894
4.9 - Medium
- August 27, 2026
Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
Spring Batch 4-6.0.x FlatFileItemReader Multi-line Record DoS
CVE-2026-47881
5.9 - Medium
- August 27, 2026
Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines for example, a CSV field that contains embedded newlines wrapped in quotes. A specially crafted input file could exploit the way the reader assembles those multi-line records to consume excessive CPU time and memory, causing the batch job to stall or run out of memory. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.0 - 5.2.6 Spring Batch 4.3.0 - 4.3.13
Resource Exhaustion
Spring Integration <7.1 JMS Header Injection via replyChannel Property
CVE-2026-47880
5.4 - Medium
- August 27, 2026
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integration MessageHeaders. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Improper Input Validation
Spring Cloud Gateway <=5.0.2 JsonToGrpcGWFF arbitrary resource location
CVE-2026-47879
7.7 - High
- August 27, 2026
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier
SSRF
Spring Batch 5.x-6.0.4 Deserialization via DefaultExecutionContextSerializer
CVE-2026-47878
5.6 - Medium
- August 27, 2026
DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowlist. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.6 and earlier
Marshaling, Unmarshaling
Spring Security Auth Server XSS via unencoded consent page (7.0.07.0.6)
CVE-2026-47877
8.2 - High
- August 27, 2026
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6
XSS
Spring Batch 5.2-6.0.4: Jackson RCE via Untrusted Deserialization
CVE-2026-47875
5.6 - Medium
- August 27, 2026
Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enforce the trusted-types allowlist, allowing an attacker to craft malicious input that can lead to arbitrary code execution, including known Jackson RCE gadgets. Spring Batch 6.0.0 - 6.0.4 Spring Batch 5.2.0 - 5.2.6
Marshaling, Unmarshaling
Spring Integration: Unsafe deserialization in SerializingHttpMessageConverter (<7.1.0)
CVE-2026-47864
6.4 - Medium
- August 27, 2026
SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serializable type is read directly via readObject(). If an application using this converter on an inbound HTTP endpoint has any known Java deserialization "gadget" on its classpath, a remote, unauthenticated attacker can achieve arbitrary code execution. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Marshaling, Unmarshaling
Spring Data REST 3-5 vulnerable: @Id/@Version mutable via JSON Patch
CVE-2026-47849
7.1 - High
- August 27, 2026
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier
Mass Assignment
Reactor Netty 1.1-1.3 HTTP/1.1 Pipelining Memory Exhaustion
CVE-2026-47874
5.3 - Medium
- August 26, 2026
The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Allocation of Resources Without Limits or Throttling
Unauthenticated Remote UDP Injection via Spring Integration UDP Inbound Adapter 5.5.21-7.1.0
CVE-2026-47861
6.3 - Medium
- August 26, 2026
An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
SSRF
Reactor Core 3.8.x bufferTimeout DoS (fairBackpressure)
CVE-2026-47863
5.9 - Medium
- August 26, 2026
In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier
Infinite Loop
Spring Integration 6.4-7.1.0 ZipTransformer Path Traversal via file_name Header
CVE-2026-47862
5.4 - Medium
- August 26, 2026
An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Directory traversal
Spring AMQP 4.1.0 JVM Crash via Message Decompression (CVE-2026-47860)
CVE-2026-47860
6.5 - Medium
- August 26, 2026
An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Spring Integration 7.1.0+ RFC6587SyslogDeserializer Byte Array CVE-2026-47859
CVE-2026-47859
5.4 - Medium
- August 26, 2026
RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size with no upper bound. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Allocation of Resources Without Limits or Throttling
Reactor Core DoS via Flux.windowTimeout fairBackpressure (3.8.6)
CVE-2026-47857
5.9 - Medium
- August 26, 2026
In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier
Integer Overflow or Wraparound
Spring Integration 6.5.x-7.1 JSON Deser via json_TypeId__ Header (No Whitelist)
CVE-2026-47856
6.3 - Medium
- August 26, 2026
Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Marshaling, Unmarshaling
Spring AI Local Path Traversal in ONNX Model Loading (1.01.0.9,1.1.01.1.8,2.0.0)
CVE-2026-47852
7.5 - High
- August 26, 2026
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
Insecure Temporary File
Spring AI <2.0 StackOverflow via cyclic PDF TOC
CVE-2026-47851
7.5 - High
- August 26, 2026
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
Stack Exhaustion
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for VMware Spring Framework or by VMware? Click the Watch button to subscribe.