GHSA-3qwq-q9vm-5j42
Spring Cloud Config Server: Path Traversal via Profile Parameter Allows Arbitrary File Access
CVEs:GHSA-3qwq-q9vm-5j42
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Spring Cloud Config Server: Path Traversal via Profile Parameter Allows Arbitrary File Access
CVEs:GHSA-3qwq-q9vm-5j42
Spring Cloud Config Server: Path Traversal via Profile Parameter Allows Arbitrary File Access
CVEs:CVE-2026-22739
Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression key
CVEs:GHSA-fvh3-672c-7p6c
Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression key
CVEs:CVE-2026-22738
JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter
CVEs:GHSA-rp9g-qx29-88cp
JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter
CVEs:CVE-2026-22729
SQL Injection in Spring AI MariaDBFilterExpressionConverter
CVEs:GHSA-c267-rfvc-mvpm
SQL Injection in Spring AI MariaDBFilterExpressionConverter
CVEs:CVE-2026-22730
Spring Security HTTP Headers Are not Written Under Some Conditions
CVEs:GHSA-mf92-479x-3373
Spring Security HTTP Headers Are not Written Under Some Conditions
CVEs:CVE-2026-22732
Spring Framework Improper Path Limitation with Script View Templates
CVEs:GHSA-4773-3jfm-qmx3
Spring Framework Improper Path Limitation with Script View Templates
CVEs:CVE-2026-22737
Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
CVEs:GHSA-mgvc-8q2h-5pgc
Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
CVEs:CVE-2026-22733
Spring AI: Insufficient Validation causes SSRF when processing multimodal messages with user-supplied URLs
CVEs:GHSA-mhrg-94vw-45c5
Spring AI: Insufficient Validation causes SSRF when processing multimodal messages with user-supplied URLs
CVEs:CVE-2026-22742
Spring Boot has an Authentication Bypass under Actuator Health groups paths
CVEs:GHSA-8hfc-fq58-r658
Spring Boot has an Authentication Bypass under Actuator Health groups paths
CVEs:CVE-2026-22731
Spring AI Redis Store has TAG Field Query Injection Through Improper Neutralization of Special Characters
CVEs:GHSA-44f4-gvwj-6qg3
Spring AI has a Cypher Injection vulnerability in Neo4jVectorFilterExpressionConverter
CVEs:GHSA-7cj7-rcw6-p68v
Spring AI has a Cypher Injection vulnerability in Neo4jVectorFilterExpressionConverter
CVEs:CVE-2026-22743
Spring AI Redis Store has TAG Field Query Injection Through Improper Neutralization of Special Characters
CVEs:CVE-2026-22744
Cloudfoundry UAA has logic error in the token revocation endpoint implementation
CVEs:GHSA-6wcw-r64p-qrrw
Cloudfoundry UAA has logic error in the token revocation endpoint implementation
CVEs:CVE-2026-22723
GHSA-22rx-x655-8pgg
CVEs:GHSA-22rx-x655-8pgg
CVEs:CVE-2026-22727
Spring MVC and WebFlux has Server Sent Event stream corruption
CVEs:GHSA-6hcq-hmm3-jj3c
Spring MVC and WebFlux has Server Sent Event stream corruption
CVEs:CVE-2026-22735
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.