Search CVE reports


Toggle filters

1 – 10 of 1355 results


CVE-2026-22737

Medium priority
Needs evaluation

(Use of Java scripting engine enabled (e.g. JRuby, Jython) template vie ...)

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-22735

Medium priority
Needs evaluation

(Spring MVC and WebFlux applications are vulnerable to stream corruptio ...)

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-41254

Medium priority
Needs evaluation

STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: * 6.2.0 - 6.2.11 * 6.1.0 - 6.1.23 * ...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-41249

Medium priority
Needs evaluation

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-41242

Medium priority
Needs evaluation

Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when all the following are true: * the application is...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-41234

Medium priority
Needs evaluation

Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset,...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-22233

Medium priority
Needs evaluation

CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-4432

Medium priority
Needs evaluation

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely...

1 affected package

rust-ring

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-ring Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2025-22235

Medium priority
Needs evaluation

EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. Your application may be affected by this if all the following conditions are...

1 affected package

libspring-java

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libspring-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-13939

Medium priority
Needs evaluation

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different,...

1 affected package

libstring-compare-constanttime-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libstring-compare-constanttime-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages