Vmware
Vmware Spring Boot: vulnerabilities and CVEs
Vmware Spring Boot has 26 published vulnerabilities, 15 of them in the last 12 months. 6 are rated critical and 0 are listed by CISA as actively exploited.
CVEs26
Last 12 months15
Critical6
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-88620 | Medium (4.3) | 0.28% | — | Sep 15, 2026 | SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope… |
| CVE-2026-82265 | Medium (6.9) | 0.45% | — | Aug 28, 2026 | Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables,… |
| CVE-2026-50201 | Medium (6.5) | 0.40% | — | Jun 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore… |
| CVE-2026-41001 | Medium (5.3) | 0.13% | — | Jun 11, 2026 | Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create… |
| CVE-2026-40992 | Medium (5) | 0.18% | — | Jun 11, 2026 | Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected.… |
| CVE-2026-40977 | Medium (6.7) | 0.15% | — | Apr 28, 2026 | When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring… |
| CVE-2026-40976 | Critical (9.1) | 0.54% | — | Apr 28, 2026 | In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring… |
| CVE-2026-40975 | High (7.5) | 0.41% | — | Apr 28, 2026 | Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable… |
| CVE-2026-40974 | Critical (9.8) | 0.36% | — | Apr 28, 2026 | Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15… |
| CVE-2026-40973 | High (7) | 0.13% | — | Apr 28, 2026 | A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across… |
| CVE-2026-40972 | High (7.5) | 0.33% | — | Apr 28, 2026 | An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining… |
| CVE-2026-40971 | Critical (9.1) | 0.30% | — | Apr 27, 2026 | When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13… |
| CVE-2026-40970 | Medium (6.8) | 0.21% | — | Apr 27, 2026 | When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to… |
| CVE-2026-22733 | High (8.1) | 0.36% | — | Mar 20, 2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator… |
| CVE-2026-22731 | High (8.1) | 0.33% | — | Mar 19, 2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a… |
| CVE-2025-8738 | Medium (5.5) | 0.37% | — | Aug 8, 2025 | A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /actuator of the component Spring Actuator Interface. The… |
| CVE-2025-46822 | High (7.7) | 4.0% | — | May 21, 2025 | OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms… |
| CVE-2024-52302 | High (8.7) | 3.4% | — | Nov 14, 2024 | common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint… |
| CVE-2023-34055 | Medium (6.5) | 1.2% | — | Nov 28, 2023 | In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application… |
| CVE-2023-20883 | High (7.5) | 0.91% | — | May 26, 2023 | In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse… |
| CVE-2023-20873 | Critical (9.8) | 1.1% | — | Apr 20, 2023 | In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply… |
| CVE-2023-22602 | High (7.5) | 1.6% | — | Jan 14, 2023 | When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different… |
| CVE-2022-27772 | High (7.8) | 0.60% | — | Mar 30, 2022 | spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the… |
| CVE-2021-26987 | Critical (9.8) | 2.4% | — | Mar 15, 2021 | Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code… |
| CVE-2018-1196 | Medium (5.9) | 1.2% | — | Mar 19, 2018 | Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is… |
| CVE-2017-8046 | Critical (9.8) | 75% | — | Jan 4, 2018 | Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted… |