GHSA-8v8j-3hxp-93wr
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
CVEs:GHSA-8v8j-3hxp-93wr
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
CVEs:GHSA-8v8j-3hxp-93wr
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
CVEs:CVE-2026-40976
Spring Framework DoS with Multipart Temp Files in WebFlux
CVEs:GHSA-5843-p793-ghmm
Spring Framework DoS with Multipart Temp Files in WebFlux
CVEs:CVE-2026-22740
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
CVEs:GHSA-6p4f-wcwh-5vvm
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
CVEs:CVE-2026-22745
Spring Boot's random value property source uses a weak PRNG unsuitable for secrets
CVEs:GHSA-m4x9-hx6x-2c43
Spring Boot's random value property source uses a weak PRNG unsuitable for secrets
CVEs:CVE-2026-40975
Spring Boot DevTools remote secret comparison is vulnerable to timing attacks
CVEs:GHSA-56v8-86gj-66jp
Spring Boot DevTools remote secret comparison is vulnerable to timing attacks
CVEs:CVE-2026-40972
Spring AI Vulnerable to OOM by attacker-controlled PDF
CVEs:GHSA-26gg-9gv2-v27j
Spring AI Vulnerable to OOM by attacker-controlled PDF
CVEs:CVE-2026-40980
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
CVEs:GHSA-wg35-8jpf-2xv3
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
CVEs:CVE-2026-22741
Spring AI's VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
CVEs:GHSA-v6x6-pjxw-3pv2
Spring AI's VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
CVEs:CVE-2026-40966
Spring Cloud Gateway's SSL bundle configuration silently bypassed
CVEs:GHSA-hwqh-2684-54fc
Spring Cloud Gateway's SSL bundle configuration silently bypassed
CVEs:CVE-2026-22750
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
CVEs:GHSA-vxf7-qj7q-83fh
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
CVEs:CVE-2026-22746
Spring Security has Potential Security Misconfiguration when Using withIssuerLocation
CVEs:GHSA-cvc6-q2cp-2xhw
Spring Security has Potential Security Misconfiguration when Using withIssuerLocation
CVEs:CVE-2026-22748
Spring Boot's Cassandra SSL auto-configuration disables TLS hostname verification
CVEs:GHSA-mqvw-jfmh-93qq
Spring Boot's Cassandra SSL auto-configuration disables TLS hostname verification
CVEs:CVE-2026-40974
Spring Boot's RabbitMQ auto-configuration doesn't perform hostname verification when connecting to the RabbitMQ broker
CVEs:GHSA-9vc8-qppq-wvxc
Spring Boot's RabbitMQ auto-configuration doesn't perform hostname verification when connecting to the RabbitMQ broker
CVEs:CVE-2026-40971
Spring Boot accepts predictable temp directory without ownership verification
CVEs:GHSA-wwpq-f5c3-7hvx
Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server.
CVEs:GHSA-c96x-rpm4-349p
Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server.
CVEs:CVE-2026-40970
Spring Boot accepts predictable temp directory without ownership verification
CVEs:CVE-2026-40973
Spring Boot's PID file write follows symlinks at predictable default path
CVEs:GHSA-5368-6h4h-gr29
Spring Boot's PID file write follows symlinks at predictable default path
CVEs:CVE-2026-40977
Spring AI's ONNX model cache defaults to world-writable predictable /tmp directory
CVEs:GHSA-r5hp-3cgj-j6xv
Spring AI's ONNX model cache defaults to world-writable predictable /tmp directory
CVEs:CVE-2026-40979
GHSA-vp68-f85j-5gw3
CVEs:GHSA-vp68-f85j-5gw3
CVEs:CVE-2026-22734
Spring AI has SQL Injection in CosmosDBVectorStore.doDelete()
CVEs:GHSA-63c8-m9m2-cvr3
Spring AI has SQL Injection in CosmosDBVectorStore.doDelete()
CVEs:CVE-2026-40978
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
CVEs:GHSA-2jrg-rf5x-568g
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
CVEs:CVE-2026-22747
Spring gRPC SecurityContext leaks across requests upon authorization failure
CVEs:GHSA-4g9c-3x4p-mfpp
Spring gRPC SecurityContext leaks across requests upon authorization failure
CVEs:CVE-2026-40968
Spring AI has a VectorStore FilterExpression Converter injection
CVEs:GHSA-qc4j-qjqx-vr58
Spring AI has a VectorStore FilterExpression Converter injection
CVEs:CVE-2026-40967
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules
CVEs:GHSA-4vrc-j85c-598c
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules
CVEs:CVE-2026-22754
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers
CVEs:GHSA-4wrg-8wpc-h923
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers
CVEs:CVE-2026-22753
Spring gRPC AuthenticationException messages are reflected to remote client
CVEs:GHSA-37w2-q6vh-45v6
Spring gRPC AuthenticationException messages are reflected to remote client
CVEs:CVE-2026-40969
Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
CVEs:GHSA-x2wq-9x2f-fhj7
Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
CVEs:CVE-2026-22751
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.