Spring Tools Eclipse 5.2.0- LTE Docker ports exposed on 0.0.0.0
CVE-2026-47873 Published on July 30, 2026
Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
Vulnerability Analysis
Weakness Type
Binding to an Unrestricted IP Address
The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.
Products Associated with CVE-2026-47873
Want to know whenever a new CVE is published for VMware Spring Framework? stack.watch will email you.
Affected Versions
Spring Tools for Eclipse:- Before and including 5.2.0 is affected.