Vendor
Spring vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 29 vulnerabilities in Spring: 0 in the last 7 days and 19 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-59320, was published on 27 August 2026. 4 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 19
- Critical, all time
- 2
- Exploited in the wild
- 0
About Spring
Java application framework for building enterprise applications with dependency injection and web components.
Spring technologies
Latest Spring vulnerabilities
- CVE-2026-59320: Spring AMQP link credit exhaustion in error handlermediumCVSS 6.5EPSS 0.4%
- CVE-2026-59315: Spring Cloud Config denial of service via malicious payloadsmediumCVSS 5.3EPSS 0.4%
- CVE-2026-59307: Spring Integration JdbcMessageStore deserialization bypasshighCVSS 8EPSS 0.4%
- CVE-2026-59306: Spring Cloud Stream deserialization of untrusted typeslowCVSS 3.1EPSS 0.2%
- CVE-2026-59303: Spring Cloud Stream unbounded dynamic destination cachelowCVSS 3.1EPSS 0.2%
- CVE-2026-59299: Spring Cloud Function composition lookup function poisoninglowCVSS 3.1EPSS 0.2%
- CVE-2026-59298: Spring Cloud Function improper HTTP header filteringlowCVSS 3.1EPSS 0.2%
- CVE-2026-59297: Spring Cloud Function isSecure() implementation does not verify HTTPS schemelowCVSS 3.1EPSS 0.1%
- CVE-2026-59272: Spring AMQP TLS certificate validation bypassmediumCVSS 6.8EPSS 0.3%
- CVE-2026-59355: Spring Authorization Server open redirect via request_uri parametermediumCVSS 6.1EPSS 0.2%
- CVE-2026-47894: Spring Cloud Config Server path traversal in native repositorymediumCVSS 4.9EPSS 0.5%
- CVE-2026-47877: Spring Security Authorization Server XSS in default consent pagehighCVSS 8.2EPSS 0.3%
- CVE-2026-47875: Spring Batch deserialization bypass in Jackson2ExecutionContextStringSerializermediumCVSS 5.6EPSS 0.4%
- CVE-2026-47864: Spring Integration SerializingHttpMessageConverter unsafe deserializationmediumCVSS 6.4EPSS 5.9%
- CVE-2026-47862: Spring Integration path traversal in ZipTransformermediumCVSS 5.4EPSS 0.3%
- CVE-2026-47860: Spring AMQP denial of service via decompression bombmediumCVSS 6.5EPSS 0.4%
- CVE-2026-47859: Spring Integration RFC6587SyslogDeserializer denial of servicemediumCVSS 5.4EPSS 0.3%
- CVE-2026-59323: Spring Micrometer Tracing denial of service in W3C baggage parsingmediumCVSS 5.3EPSS 0.4%
- CVE-2026-22752: Spring Security Spring Authorization Server authentication bypasscriticalCVSS 9.6
- CVE-2026-40998: VMware Spring Web Services XXE in Jaxp13XPathTemplatehighCVSS 8.2EPSS 0.4%
- CVE-2026-41728: VMware Spring Data REST improper access control in JSON PatchhighCVSS 7.5EPSS 0.4%
- CVE-2026-41695: VMware Spring Data Commons denial of service in MappingContexthighCVSS 7.5EPSS 0.5%
- CVE-2026-41008: VMware Spring Security Authorization Server open redirect in authorization endpointmediumCVSS 6.1EPSS 0.3%
- CVE-2026-40991: VMware Spring REST Docs XXE injection in webtestclient and restassuredmediumCVSS 5.9EPSS 0.3%
- CVE-2026-41007: VMware Spring HATEOAS resource exhaustion in StringLinkRelation cachehighCVSS 7.5EPSS 0.5%
Most severe Spring vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-22752: Spring Security Spring Authorization Server authentication bypasscriticalCVSS 9.6
- CVE-2026-40982: VMware Spring Cloud Config directory traversal in spring-cloud-config-servercriticalCVSS 9.1EPSS 0.8%
- CVE-2026-40998: VMware Spring Web Services XXE in Jaxp13XPathTemplatehighCVSS 8.2EPSS 0.4%
- CVE-2026-47877: Spring Security Authorization Server XSS in default consent pagehighCVSS 8.2EPSS 0.3%
- CVE-2026-59307: Spring Integration JdbcMessageStore deserialization bypasshighCVSS 8EPSS 0.4%
- CVE-2026-41695: VMware Spring Data Commons denial of service in MappingContexthighCVSS 7.5EPSS 0.5%
- CVE-2026-41007: VMware Spring HATEOAS resource exhaustion in StringLinkRelation cachehighCVSS 7.5EPSS 0.5%
- CVE-2026-41728: VMware Spring Data REST improper access control in JSON PatchhighCVSS 7.5EPSS 0.4%
- CVE-2026-59272: Spring AMQP TLS certificate validation bypassmediumCVSS 6.8EPSS 0.3%
- CVE-2026-59320: Spring AMQP link credit exhaustion in error handlermediumCVSS 6.5EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 1 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 17 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/spring.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Spring vulnerabilities", https://junglewise.ai/threats/vendors/spring, 26 September 2026.