PatchSiren

Spring CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Spring CVE published 2026-06-10

CVE-2026-41717

CVE-2026-41717 is a high-severity vulnerability in Spring Data MongoDB, allowing for SpEL (Spring Expression Language) expression injection. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all placeholder. This vulnerability has a CVSS score of 8.1 and is considered HIGH severity.

HIGH Spring CVE published 2026-06-10

CVE-2026-41716

CVE-2026-41716 is a high-severity vulnerability in Spring Data that allows for heap exhaustion through repeated requests. The vulnerability is caused by the internal property-lookup cache in Spring Data accepting and permanently retaining attacker-supplied strings as cache keys. This can lead to heap exhaustion, potentially causing a denial-of-service (DoS) attack.

MEDIUM Spring CVE published 2026-06-10

CVE-2026-41714

CVE-2026-41714 is a medium-severity vulnerability affecting Spring AMQP versions 2.4.0 through 2.4.17, 3.1.0 through 3.1.15, 3.2.0 through 3.2.10, and 4.0.0 through 4.0.3. The issue arises when applications configure their broker connection via `RabbitConnectionFactoryBean.setUri(

MEDIUM Spring CVE published 2026-06-10

CVE-2026-41711

A Denial of Service (DoS) vulnerability was discovered in Spring Data Commons, which can be exploited to cause a StackOverflowException when parsing Sort parameters. This vulnerability affects multiple versions of Spring Data Commons, including 4.0.0 through 4.0.5, 3.5.0 through 3.5.11, 3.4.0 through 3.4.14, 3.3.0 through 3.3.16, 3.2.0 through 3.2.15, 3.1.0 through 3.1.14, 3.0.0 through 3.0.15, and 2.7.0 [truncated]

MEDIUM Spring CVE published 2026-06-10

CVE-2026-41706

CVE-2026-41706 is a vulnerability in Spring Security's CookieRequestCache and CookieServerRequestCache. These components store the pre-authentication request URL in a browser cookie to redirect users to their intended destination after a successful login. However, in affected versions, the full absolute URL is stored in the cookie and used without validation as the post-login redirect target. This allows [truncated]

MEDIUM Spring CVE published 2026-06-10

CVE-2026-41701

CVE-2026-41701 is a medium-severity vulnerability in Spring AMQP. The issue arises from predictable correlation IDs for replies in the RabbitTemplate.sendAndReceive() method with a fixed reply queue. This predictability stems from an internal simple counter. The affected versions include Spring AMQP 4.0.0 through 4.0.3, 3.2.0 through 3.2.10, 3.1.0 through 3.1.15, and 2.4.0 through 2.4.17.

MEDIUM Spring CVE published 2026-06-10

CVE-2026-41697

CVE-2026-41697 is a vulnerability in Spring Data Relational that allows an attacker to perform boolean-based blind data inference by supplying wildcard characters. The vulnerability affects Spring Data Relational/JDBC/R2DBC versions 4.0.0 through 4.0.5, 3.5.0 through 3.5.11, 3.4.0 through 3.4.14, 3.3.0 through 3.3.16, 3.2.0 through 3.2.15, 3.1.0 through 3.1.14, 3.0.0 through 3.0.15, and 2.4.0 through 2.4.19.

MEDIUM Spring CVE published 2026-06-10

CVE-2026-41696

CVE-2026-41696 is a vulnerability in Spring Data MongoDB that allows an attacker to break out of intended regular expression quoting by supplying a crafted string. This issue affects Spring Data MongoDB versions 5.0.0 through 5.0.5, 4.5.0 through 4.5.11, 4.4.0 through 4.4.14, 4.3.0 through 4.3.16, 4.2.0 through 4.2.15, 4.1.0 through 4.1.14, 4.0.0 through 4.0.15, and 3.4.0 through 3.4.19.

HIGH Spring CVE published 2026-06-10

CVE-2026-41695

CVE-2026-41695 is a high-severity denial of service vulnerability in Spring Data Commons. Applications using affected versions may be vulnerable to resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution. The affected versions include Spring Data Commons 4.0.0 through 4.0.5, 3.5.0 through 3.5.11, and 3.4.0 through 3.4.14.

LOW Spring CVE published 2026-06-10

CVE-2026-41694

CVE-2026-41694 is a low-severity vulnerability in Spring Security that allows attackers to craft SAML payloads and use the Service Provider as a decryption oracle. The vulnerability affects Spring Security versions 5.7.0 through 5.7.23, 5.8.0 through 5.8.25, 6.3.0 through 6.3.16, 6.4.0 through 6.4.16, 6.5.0 through 6.5.10, and 7.0.0 through 7.0.5.

HIGH Spring CVE published 2026-06-10

CVE-2026-41003

CVE-2026-41003 is a high-severity vulnerability in Spring Security, a popular Java framework for building secure web applications. An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. This vulnerability affects multiple versions of Spring Security, including 5.7.0 through 5.7.23, 5.8.0 through 5.8.25, 6.3.0 t [truncated]

HIGH Spring CVE published 2026-06-10

CVE-2026-40993

CVE-2026-40993 is a HIGH severity vulnerability in Spring Security 7.0.0 through 7.0.5. An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verification or encryption credentials (verification_credentials and encryption_credent [truncated]

MEDIUM Spring CVE published 2026-06-10

CVE-2026-40991

CVE-2026-40991 is a vulnerability in Spring REST Docs that allows for an XXE (XML External Entity) injection attack. When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next e [truncated]

HIGH Spring CVE published 2026-06-10

CVE-2026-40988

CVE-2026-40988 is a HIGH severity vulnerability in Spring Security that can lead to a denial of service via an unbounded writer that inflates the compressed SAML payload into memory. The vulnerability affects Spring Security versions 5.7.0 through 5.7.23, 5.8.0 through 5.8.25, 6.3.0 through 6.3.16, 6.4.0 through 6.4.16, 6.5.0 through 6.5.10, and 7.0.0 through 7.0.5.

HIGH Spring CVE published 2026-06-09

CVE-2026-41855

CVE-2026-41855 is a high-severity vulnerability affecting Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48. The vulnerability is caused by the `MappingJackson2MessageConverter` and `JacksonJsonMessageConverter` classes in the `org.springframework.jms.support.converter` package, which allow arbitrary class instantiation in untrusted JMS env [truncated]

MEDIUM Spring CVE published 2026-06-09

CVE-2026-41854

A medium-severity vulnerability, CVE-2026-41854, was found in Spring Framework. The issue arises from incorrect host parsing in UriComponentsBuilder, which can lead to a server-side request forgery (SSRF) attack. The affected versions are Spring Framework 7.0.0 through 7.0.7 and 6.2.0 through 6.2.18.

MEDIUM Spring CVE published 2026-06-09

CVE-2026-41853

CVE-2026-41853 is a vulnerability in Spring MVC and WebFlux applications that allows for Multipart request smuggling attacks. The affected versions are Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48. The CVSS score for this vulnerability is 5.3, with a severity rating of MEDIUM.

LOW Spring CVE published 2026-06-09

CVE-2026-41852

CVE-2026-41852 is a vulnerability in the Spring Expression Language (SpEL) evaluation logic. This vulnerability allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts. This could potentially allow an attacker to invoke unintended application logic. The affected versions include Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and [truncated]

MEDIUM Spring CVE published 2026-06-09

CVE-2026-41851

CVE-2026-41851 is a Denial of Service (DoS) vulnerability in Spring Framework. Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth.

HIGH Spring CVE published 2026-06-09

CVE-2026-41850

CVE-2026-41850 is a HIGH severity vulnerability in Spring Framework, with a CVSS score of 7.5. Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailabil [truncated]

HIGH Spring CVE published 2026-06-09

CVE-2026-41849

CVE-2026-41849 is a HIGH severity vulnerability with a CVSS score of 7.5. The vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL) and can be exploited by supplying a specially crafted SpEL expression, resulting in excessive resource consumption and a Denial of Service (DoS).

LOW Spring CVE published 2026-06-09

CVE-2026-41848

CVE-2026-41848 is a Regular Expression Denial of Service (ReDoS) vulnerability in Spring Framework. Applications may be vulnerable if an attacker provides a malicious pattern to certain methods in AntPathMatcher. The affected versions are Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.

MEDIUM Spring CVE published 2026-06-09

CVE-2026-41847

A security bypass vulnerability exists in Spring WebFlux applications when using the Kotlin Router DSL. The vulnerability affects Spring Framework versions 5.3.0 through 5.3.48.

MEDIUM Spring CVE published 2026-06-09

CVE-2026-41846

CVE-2026-41846 is a medium-severity vulnerability in Spring Framework that allows for cross-site scripting (XSS) attacks. The vulnerability affects Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48. The vulnerability occurs when user-supplied values are accepted in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags, potent [truncated]

MEDIUM Spring CVE published 2026-06-09

CVE-2026-41844

A Spring MVC or Spring WebFlux application that configures a mapping for '/**' without explicitly specifying a view name is vulnerable to a 302 redirect attack via the 'redirect:' prefix. This issue affects Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.

MEDIUM Spring CVE published 2026-06-09

CVE-2026-41843

CVE-2026-41843 is a Path Traversal vulnerability affecting Spring MVC and WebFlux applications when resolving static resources. The affected versions are Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; and 5.3.0 through 5.3.48. The CVSS score for this vulnerability is 5.9, with a severity rating of MEDIUM.

HIGH Spring CVE published 2026-06-09

CVE-2026-41842

CVE-2026-41842 is a HIGH severity vulnerability in Spring MVC and WebFlux applications, allowing for Denial of Service (DoS) attacks when resolving static resources. The vulnerability affects Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.

MEDIUM Spring CVE published 2026-06-09

CVE-2026-41841

A medium-severity vulnerability, CVE-2026-41841, was found in Spring MVC and WebFlux applications. This issue allows for Information Disclosure attacks when resolving static resources. The vulnerability affects multiple versions of the Spring Framework, including 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.

MEDIUM Spring CVE published 2026-06-09

CVE-2026-41840

A Denial of Service (DoS) vulnerability was discovered in Spring WebFlux applications when processing multipart requests. This vulnerability affects Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.

MEDIUM Spring CVE published 2026-06-09

CVE-2026-41839

A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. This vulnerability affects Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.