VendorsVMwarespring_frameworkall versions
Vulnerabilities

VMware Spring Framework

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

84CVEs
CVE-2026-41845
Spring Framework Cross-site Scripting via JavaScriptUtils
Published 2026-06-09 · Analyzed
7.1EPSS 0.002
CVE-2014-0054
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.
Published 2014-04-17 · Modified
6.8EPSS 0.914
CVE-2013-6429
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.
Published 2014-01-26 · Modified
6.8EPSS 0.906
CVE-2013-4152
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue.
Published 2014-01-23 · Modified
6.8EPSS 0.255
CVE-2011-2894
Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) accessing internal AOP interfaces, as demonstrated using deserialization of a DefaultListableBeanFactory instance to execute arbitrary commands via the java.lang.Runtime class.
Published 2011-10-04 · Modified
6.8EPSS 0.086
CVE-2013-7315
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.
Published 2014-01-23 · Modified
6.8EPSS 0.051
CVE-2022-22950
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
Published 2022-04-01 · Modified
6.5EPSS 0.361
CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
Published 2022-05-12 · Modified
6.5EPSS 0.032
CVE-2018-1257
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
Published 2018-05-11 · Modified
6.5EPSS 0.031
CVE-2023-20863
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
Published 2023-04-13 · Modified
6.5EPSS 0.011
CVE-2023-20861
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
Published 2023-03-23 · Modified
6.5EPSS 0.010
CVE-2026-22740
Spring Framework DoS with Multipart Temp Files in WebFlux
Published 2026-04-29 · Analyzed
6.5EPSS 0.003
CVE-2026-41854
Spring Framework Server-Side Request Forgery via UriComponentsBuilder
Published 2026-06-09 · Analyzed
6.5EPSS 0.001
CVE-2026-47883
Spring Framework Open Redirect in UrlHandlerFilter
Published 2026-08-27 · Analyzed
6.1EPSS 0.002
CVE-2026-59281
Spring Framework Cross-site Scripting via EscapedErrors
Published 2026-08-27 · Analyzed
6.1EPSS 0.002
CVE-2026-47887
Spring Framework Open Redirect in UrlFileNameViewController
Published 2026-08-27 · Analyzed
6.1EPSS 0.002
CVE-2026-41846
Spring Framework Cross-site Scripting via JSP Form Tags
Published 2026-06-09 · Analyzed
6.1EPSS 0.002
CVE-2026-41844
Spring Framework Open Redirect in Spring MVC and WebFlux
Published 2026-06-09 · Analyzed
6.1EPSS 0.001
CVE-2018-1271
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.
Published 2018-04-06 · Modified
5.9EPSS 0.344
CVE-2018-11039
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
Published 2018-06-25 · Modified
5.9EPSS 0.027
CVE-2026-22737
Spring Framework Improper Path Limitation with Script View Templates
Published 2026-03-19 · Analyzed
5.9EPSS 0.004
CVE-2026-41843
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
Published 2026-06-09 · Analyzed
5.9EPSS 0.004
CVE-2026-41841
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
Published 2026-06-09 · Analyzed
5.9EPSS 0.003
CVE-2026-41840
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
Published 2026-06-09 · Analyzed
5.9EPSS 0.003
CVE-2015-3192
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
Published 2016-07-12 · Modified
5.5EPSS 0.026
CVE-2022-22968
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.
Published 2022-04-14 · Modified
5.3EPSS 0.057
CVE-2018-1199
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. In this particular attack, different character encodings used in path parameters allows secured Spring MVC static resource URLs to be bypassed.
Published 2018-03-16 · Modified
5.3EPSS 0.029
CVE-2020-5397
CSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFlux
Published 2020-01-17 · Modified
5.3EPSS 0.024
CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Published 2022-05-12 · Modified
5.3EPSS 0.020
CVE-2024-38820
CVE-2024-38820: Spring Framework DataBinder Case Sensitive Match Exception
Published 2024-10-18 · Modified
5.3EPSS 0.006
CVE-2026-22745
CVE-2026-22745 : Denial of service in static resource handling on Windows platforms
Published 2026-04-29 · Analyzed
5.3EPSS 0.003
CVE-2026-41853
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
Published 2026-06-09 · Analyzed
5.3EPSS 0.002
CVE-2026-41852
Spring Framework Arbitrary Method Invocation in SpEL Expressions
Published 2026-06-09 · Analyzed
5.3EPSS 0.002
CVE-2026-41847
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
Published 2026-06-09 · Analyzed
5.3EPSS 0.002
CVE-2014-3625
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
Published 2014-11-20 · Modified
5.0EPSS 0.103
CVE-2015-0201
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
Published 2015-03-10 · Modified
5.0EPSS 0.019
CVE-2021-22096
In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
Published 2021-10-28 · Modified
4.3EPSS 0.014
CVE-2021-22060
In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.
Published 2022-01-07 · Modified
4.3EPSS 0.008
CVE-2024-38808
CVE-2024-38808: Spring Expression DoS Vulnerability
Published 2024-08-20 · Analyzed
4.3EPSS 0.006
CVE-2026-59280
Spring Framework Path Traversal via Backslash in SpringTemplateLoader
Published 2026-08-27 · Analyzed
4.3EPSS 0.002
← Prev2 / 3Next →