{"schema_version":1,"title":"VMware Spring Boot vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in VMware Spring Boot: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-41001, was published on 11 June 2026.","url":"https://junglewise.ai/threats/technologies/spring-boot","json_url":"https://junglewise.ai/threats/technologies/spring-boot.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/spring-boot","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":11,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":11},"latest":[{"cve":"CVE-2026-41001","cvss":5.3,"epss":0.0013,"slug":"cve-2026-41001-vmware-spring-boot-insecure-directory-in","title":"VMware Spring Boot insecure directory in ArtemisEmbeddedConfigurationFactory","severity":"medium","exploited":false,"published_at":"2026-06-11T07:16:28.163+00:00","url":"https://junglewise.ai/threats/cve-2026-41001-vmware-spring-boot-insecure-directory-in"},{"cve":"CVE-2026-40992","cvss":5,"epss":0.0019,"slug":"cve-2026-40992-vmware-spring-boot-improper-certificate-validation-in-mail-auto","title":"VMware Spring Boot improper certificate validation in Mail auto-configuration","severity":"medium","exploited":false,"published_at":"2026-06-11T07:16:27.177+00:00","url":"https://junglewise.ai/threats/cve-2026-40992-vmware-spring-boot-improper-certificate-validation-in-mail-auto"},{"cve":"CVE-2026-40977","cvss":4.7,"epss":0.0015,"slug":"cve-2026-40977-vmware-spring-boot-link-resolution-vulnerability-in","title":"VMware Spring Boot link resolution vulnerability in ApplicationPidFileWriter","severity":"medium","exploited":false,"published_at":"2026-04-28T00:16:24.947+00:00","url":"https://junglewise.ai/threats/cve-2026-40977-vmware-spring-boot-link-resolution-vulnerability-in"},{"cve":"CVE-2026-40976","cvss":9.1,"epss":0.0054,"slug":"cve-2026-40976-spring-boot-authentication-bypass-in-default-web-security-filter","title":"Spring Boot authentication bypass in default web security filter chain","severity":"critical","exploited":false,"published_at":"2026-04-28T00:16:24.803+00:00","url":"https://junglewise.ai/threats/cve-2026-40976-spring-boot-authentication-bypass-in-default-web-security-filter"},{"cve":"CVE-2026-40975","cvss":4.8,"epss":0.0041,"slug":"cve-2026-40975-spring-boot-weak-prng-in-random-value-property-source","title":"Spring Boot weak PRNG in random value property source","severity":"medium","exploited":false,"published_at":"2026-04-28T00:16:24.657+00:00","url":"https://junglewise.ai/threats/cve-2026-40975-spring-boot-weak-prng-in-random-value-property-source"},{"cve":"CVE-2026-40974","cvss":5,"epss":0.0036,"slug":"cve-2026-40974-vmware-spring-boot-improper-certificate-validation-in-cassandra","title":"VMware Spring Boot Improper Certificate Validation in Cassandra auto-configuration","severity":"medium","exploited":false,"published_at":"2026-04-28T00:16:24.523+00:00","url":"https://junglewise.ai/threats/cve-2026-40974-vmware-spring-boot-improper-certificate-validation-in-cassandra"},{"cve":"CVE-2026-40973","cvss":7,"epss":0.0013,"slug":"cve-2026-40973-vmware-spring-boot-insecure-temporary-directory-in","title":"VMware Spring Boot insecure temporary directory in ApplicationTemp","severity":"high","exploited":false,"published_at":"2026-04-28T00:16:24.357+00:00","url":"https://junglewise.ai/threats/cve-2026-40973-vmware-spring-boot-insecure-temporary-directory-in"},{"cve":"CVE-2026-40972","cvss":7.5,"epss":0.0033,"slug":"cve-2026-40972-vmware-spring-boot-timing-attack-in-devtools-remote-secret","title":"VMware Spring Boot timing attack in DevTools remote secret comparison","severity":"high","exploited":false,"published_at":"2026-04-28T00:16:24.21+00:00","url":"https://junglewise.ai/threats/cve-2026-40972-vmware-spring-boot-timing-attack-in-devtools-remote-secret"},{"cve":"CVE-2026-40971","cvss":5,"epss":0.003,"slug":"cve-2026-40971-vmware-spring-boot-improper-certificate-validation-in-rabbitmq","title":"VMware Spring Boot improper certificate validation in RabbitMQ auto-configuration","severity":"medium","exploited":false,"published_at":"2026-04-27T23:16:03.403+00:00","url":"https://junglewise.ai/threats/cve-2026-40971-vmware-spring-boot-improper-certificate-validation-in-rabbitmq"},{"cve":"CVE-2026-40970","cvss":5,"epss":0.0021,"slug":"cve-2026-40970-vmware-spring-boot-improper-certificate-validation-in","title":"VMware Spring Boot improper certificate validation in Elasticsearch auto-configuration","severity":"medium","exploited":false,"published_at":"2026-04-27T19:16:52.967+00:00","url":"https://junglewise.ai/threats/cve-2026-40970-vmware-spring-boot-improper-certificate-validation-in"},{"cve":"CVE-2026-22731","cvss":8.2,"epss":0.0033,"slug":"cve-2026-22731-vmware-spring-boot-authentication-bypass-in-actuator-health","title":"VMware Spring Boot authentication bypass in Actuator Health groups","severity":"high","exploited":false,"published_at":"2026-03-20T00:31:28+00:00","url":"https://junglewise.ai/threats/cve-2026-22731-vmware-spring-boot-authentication-bypass-in-actuator-health"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"VMware RabbitMQ","slug":"vmware-rabbitmq","vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/vmware-rabbitmq"},{"name":"VMware Spring Framework","slug":"spring-framework","vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/spring-framework"},{"name":"VMware Cloud Foundation","slug":"cloud-foundation","vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/cloud-foundation"},{"name":"VMware Spring Security","slug":"spring-security","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/spring-security"},{"name":"VMware Spring AI","slug":"spring-ai","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/spring-ai"},{"name":"VMware ESXi","slug":"esxi","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/esxi"},{"name":"VMware Avi Load Balancer","slug":"avi-load-balancer","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/avi-load-balancer"},{"name":"VMware Spring for GraphQL","slug":"spring-for-graphql","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/spring-for-graphql"},{"name":"VMware Spring Integration","slug":"spring-integration","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/spring-integration"},{"name":"VMware vSphere Foundation","slug":"vsphere-foundation","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/vsphere-foundation"},{"name":"VMware Spring Web Services","slug":"web-services","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/web-services"},{"name":"VMware Fusion","slug":"fusion","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/fusion"}],"technology":{"hub":true,"name":"VMware Spring Boot","slug":"spring-boot","vendor":{"name":"VMware","slug":"vmware","url":"https://junglewise.ai/threats/vendors/vmware"},"aliases":[],"category":"framework","homepage":"https://spring.io/projects/spring-boot","repo_url":"https://github.com/spring-projects/spring-boot","description":"Spring-based Java application framework for building standalone, production-grade applications with embedded servers and minimal configuration.","url":"https://junglewise.ai/threats/technologies/spring-boot"},"most_severe":[{"cve":"CVE-2026-40976","cvss":9.1,"epss":0.0054,"slug":"cve-2026-40976-spring-boot-authentication-bypass-in-default-web-security-filter","title":"Spring Boot authentication bypass in default web security filter chain","severity":"critical","exploited":false,"published_at":"2026-04-28T00:16:24.803+00:00","url":"https://junglewise.ai/threats/cve-2026-40976-spring-boot-authentication-bypass-in-default-web-security-filter"},{"cve":"CVE-2026-22731","cvss":8.2,"epss":0.0033,"slug":"cve-2026-22731-vmware-spring-boot-authentication-bypass-in-actuator-health","title":"VMware Spring Boot authentication bypass in Actuator Health groups","severity":"high","exploited":false,"published_at":"2026-03-20T00:31:28+00:00","url":"https://junglewise.ai/threats/cve-2026-22731-vmware-spring-boot-authentication-bypass-in-actuator-health"},{"cve":"CVE-2026-40972","cvss":7.5,"epss":0.0033,"slug":"cve-2026-40972-vmware-spring-boot-timing-attack-in-devtools-remote-secret","title":"VMware Spring Boot timing attack in DevTools remote secret comparison","severity":"high","exploited":false,"published_at":"2026-04-28T00:16:24.21+00:00","url":"https://junglewise.ai/threats/cve-2026-40972-vmware-spring-boot-timing-attack-in-devtools-remote-secret"},{"cve":"CVE-2026-40973","cvss":7,"epss":0.0013,"slug":"cve-2026-40973-vmware-spring-boot-insecure-temporary-directory-in","title":"VMware Spring Boot insecure temporary directory in ApplicationTemp","severity":"high","exploited":false,"published_at":"2026-04-28T00:16:24.357+00:00","url":"https://junglewise.ai/threats/cve-2026-40973-vmware-spring-boot-insecure-temporary-directory-in"},{"cve":"CVE-2026-41001","cvss":5.3,"epss":0.0013,"slug":"cve-2026-41001-vmware-spring-boot-insecure-directory-in","title":"VMware Spring Boot insecure directory in ArtemisEmbeddedConfigurationFactory","severity":"medium","exploited":false,"published_at":"2026-06-11T07:16:28.163+00:00","url":"https://junglewise.ai/threats/cve-2026-41001-vmware-spring-boot-insecure-directory-in"},{"cve":"CVE-2026-40974","cvss":5,"epss":0.0036,"slug":"cve-2026-40974-vmware-spring-boot-improper-certificate-validation-in-cassandra","title":"VMware Spring Boot Improper Certificate Validation in Cassandra auto-configuration","severity":"medium","exploited":false,"published_at":"2026-04-28T00:16:24.523+00:00","url":"https://junglewise.ai/threats/cve-2026-40974-vmware-spring-boot-improper-certificate-validation-in-cassandra"},{"cve":"CVE-2026-40971","cvss":5,"epss":0.003,"slug":"cve-2026-40971-vmware-spring-boot-improper-certificate-validation-in-rabbitmq","title":"VMware Spring Boot improper certificate validation in RabbitMQ auto-configuration","severity":"medium","exploited":false,"published_at":"2026-04-27T23:16:03.403+00:00","url":"https://junglewise.ai/threats/cve-2026-40971-vmware-spring-boot-improper-certificate-validation-in-rabbitmq"},{"cve":"CVE-2026-40970","cvss":5,"epss":0.0021,"slug":"cve-2026-40970-vmware-spring-boot-improper-certificate-validation-in","title":"VMware Spring Boot improper certificate validation in Elasticsearch auto-configuration","severity":"medium","exploited":false,"published_at":"2026-04-27T19:16:52.967+00:00","url":"https://junglewise.ai/threats/cve-2026-40970-vmware-spring-boot-improper-certificate-validation-in"},{"cve":"CVE-2026-40992","cvss":5,"epss":0.0019,"slug":"cve-2026-40992-vmware-spring-boot-improper-certificate-validation-in-mail-auto","title":"VMware Spring Boot improper certificate validation in Mail auto-configuration","severity":"medium","exploited":false,"published_at":"2026-06-11T07:16:27.177+00:00","url":"https://junglewise.ai/threats/cve-2026-40992-vmware-spring-boot-improper-certificate-validation-in-mail-auto"},{"cve":"CVE-2026-40975","cvss":4.8,"epss":0.0041,"slug":"cve-2026-40975-spring-boot-weak-prng-in-random-value-property-source","title":"Spring Boot weak PRNG in random value property source","severity":"medium","exploited":false,"published_at":"2026-04-28T00:16:24.657+00:00","url":"https://junglewise.ai/threats/cve-2026-40975-spring-boot-weak-prng-in-random-value-property-source"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}