Package impact

java Maven / org.springframework:spring-webmvc

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2014-0225 high 8.8 8.8 9y ago When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references… debianjava
CVE-2016-9878 high 7.5 7.5 10y ago An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result expose… debianjava
CVE-2014-0054 medium 6.8 12y ago The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbit… debianjava
CVE-2026-22745 medium 5.3 5.3 29d ago Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources debianjava
CVE-2014-3625 medium 5.0 12y ago Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspeci… debianjava
CVE-2014-1904 medium 4.3 12y ago Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary … debianjava
CVE-2026-22741 low 3.1 3.1 29d ago Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. debianjava
CVE-2022-22965 unknown 1.5 4y ago Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. debianjava
CVE-2026-22737 unknown 2mo ago Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations … debianjava
CVE-2026-22735 unknown 2mo ago Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16,… debianjava
CVE-2025-41242 unknown 9mo ago Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when all the following ar… debianjava
CVE-2024-38819 unknown 1y ago Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain … debianjava
CVE-2024-38828 unknown 2y ago Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack. debianjava
CVE-2024-38816 unknown 2y ago Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain … debianjava
CVE-2023-34053 unknown 3y ago In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is … debianjava
CVE-2023-20860 unknown 3y ago Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spr… debianjava
CVE-2020-5397 unknown 6y ago Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) … debianjava
CVE-2020-5398 unknown 6y ago In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it … debianjava