Vmware
Vmware Spring Framework: vulnerabilidades y CVE
Vmware Spring Framework tiene 88 vulnerabilidades publicadas, 41 de ellas en los últimos 12 meses. 12 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE88
Últimos 12 meses41
Críticas12
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22965 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-59314 | Baja (3.7) | 0.26% | — | 27 ago 2026 | Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0… |
| CVE-2026-59313 | Crítica (9.8) | 0.56% | — | 27 ago 2026 | Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 -… |
| CVE-2026-59283 | Crítica (9.1) | 0.55% | — | 27 ago 2026 | Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 -… |
| CVE-2026-59282 | Alta (7.5) | 0.46% | — | 27 ago 2026 | Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 -… |
| CVE-2026-59281 | Media (6.1) | 0.25% | — | 27 ago 2026 | Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors… |
| CVE-2026-59280 | Media (4.3) | 0.35% | — | 27 ago 2026 | Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve… |
| CVE-2026-47893 | Alta (7.5) | 0.42% | — | 27 ago 2026 | A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework… |
| CVE-2026-47892 | Crítica (9.8) | 0.53% | — | 27 ago 2026 | A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19… |
| CVE-2026-47891 | Crítica (9.8) | 0.52% | — | 27 ago 2026 | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring… |
| CVE-2026-47890 | Crítica (9.8) | 0.56% | — | 27 ago 2026 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 |
| CVE-2026-47889 | Alta (7.5) | 0.43% | — | 27 ago 2026 | A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 |
| CVE-2026-47888 | Alta (7.5) | 0.46% | — | 27 ago 2026 | A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring… |
| CVE-2026-47887 | Media (6.1) | 0.24% | — | 27 ago 2026 | A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework… |
| CVE-2026-47886 | Alta (7.5) | 0.46% | — | 27 ago 2026 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand… |
| CVE-2026-47885 | Alta (7.5) | 0.37% | — | 27 ago 2026 | The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 |
| CVE-2026-47884 | Crítica (9.8) | 0.60% | — | 27 ago 2026 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework… |
| CVE-2026-47883 | Media (6.1) | 0.26% | — | 27 ago 2026 | UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8… |
| CVE-2026-41855 | Crítica (9.8) | 0.48% | — | 9 jun 2026 | In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation,… |
| CVE-2026-41854 | Media (6.5) | 0.21% | — | 9 jun 2026 | Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions:… |
| CVE-2026-41853 | Media (5.3) | 0.31% | — | 9 jun 2026 | Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. |
| CVE-2026-41852 | Media (5.3) | 0.26% | — | 9 jun 2026 | A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended… |
| CVE-2026-41851 | Alta (7.5) | 0.46% | — | 9 jun 2026 | Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth.… |
| CVE-2026-41850 | Alta (7.5) | 0.46% | — | 9 jun 2026 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger… |
| CVE-2026-41849 | Alta (7.5) | 0.46% | — | 9 jun 2026 | An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource… |
| CVE-2026-41848 | Alta (7.5) | 0.40% | — | 9 jun 2026 | Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in… |
| CVE-2026-41847 | Media (5.3) | 0.26% | — | 9 jun 2026 | Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48. |
| CVE-2026-41846 | Media (6.1) | 0.24% | — | 9 jun 2026 | Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site… |
| CVE-2026-41845 | Media (6.1) | 0.28% | — | 9 jun 2026 | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions:… |
| CVE-2026-41844 | Media (6.1) | 0.23% | — | 9 jun 2026 | A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external… |
| CVE-2026-41843 | Media (5.9) | 0.39% | — | 9 jun 2026 | Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.