GHSA-j388-8rm5-p97f
GHSA-j388-8rm5-p97f
CVEs:GHSA-j388-8rm5-p97f
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
GHSA-j388-8rm5-p97f
CVEs:GHSA-j388-8rm5-p97f
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
CVEs:GHSA-2827-2mxx-j8pv
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
CVEs:GHSA-792x-6vq6-j8r9
Micrometer HTTP server instrumentations DoS
CVEs:GHSA-g3pr-3p32-fp23
Micrometer gRPC server instrumentation DoS
CVEs:GHSA-w737-wx49-qj23
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
CVEs:GHSA-xq69-5h5v-x9x4
GHSA-px92-q6rc-6mwv
CVEs:GHSA-px92-q6rc-6mwv
GHSA-85qj-f5wg-rwp9
CVEs:GHSA-85qj-f5wg-rwp9
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
CVEs:GHSA-x23c-287f-qqv5
GHSA-9cjf-w9mw-93r3
CVEs:GHSA-9cjf-w9mw-93r3
GHSA-whpp-xv3h-rwxf
CVEs:GHSA-whpp-xv3h-rwxf
GHSA-5x25-c2rf-f2jx
CVEs:GHSA-5x25-c2rf-f2jx
GHSA-9fw2-h3hf-293r
CVEs:GHSA-9fw2-h3hf-293r
Spring Framework Algorithmic Denial of Service via SpEL Expressions
CVEs:GHSA-r5w3-xv2f-j59q
Spring Framework Denial of Service via Unbounded Cache in SpEL
CVEs:GHSA-wxpp-56q6-5pcg
GHSA-2mpf-m756-hxjm
CVEs:GHSA-2mpf-m756-hxjm
GHSA-phxq-526m-79px
CVEs:GHSA-phxq-526m-79px
GHSA-gg69-9wwp-6jx2
CVEs:GHSA-gg69-9wwp-6jx2
GHSA-qc5f-2h9q-7m2g
CVEs:GHSA-qc5f-2h9q-7m2g
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
CVEs:GHSA-72pg-x5f8-j25j
GHSA-5m4m-73w9-8433
CVEs:GHSA-5m4m-73w9-8433
GHSA-m69x-pw9p-7j3q
CVEs:GHSA-m69x-pw9p-7j3q
GHSA-5whc-4q84-fj73
CVEs:GHSA-5whc-4q84-fj73
Spring Framework Denial of Service via AntPathMatcher
CVEs:GHSA-659m-px2c-25wj
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
CVEs:GHSA-mq64-j8f9-9gcj
GHSA-cv39-x4c6-hhp2
CVEs:GHSA-cv39-x4c6-hhp2
GHSA-cmwh-w62w-r2mf
CVEs:GHSA-cmwh-w62w-r2mf
Spring HATEOAS heap exhaustion through unbounded internal caching
CVEs:GHSA-439x-6767-44cv
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
CVEs:GHSA-xvfq-4q6q-gxx7
GHSA-5vpf-xvv7-c8vh
CVEs:GHSA-5vpf-xvv7-c8vh
GHSA-26m2-9g2q-v45q
CVEs:GHSA-26m2-9g2q-v45q
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
CVEs:GHSA-7fxc-486f-32q9
GHSA-x863-p983-p4f7
CVEs:GHSA-x863-p983-p4f7
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
CVEs:GHSA-775g-4xr8-78h8
GHSA-hc43-m36c-8v33
CVEs:GHSA-hc43-m36c-8v33
Spring LDAP has Authentication Bypass with Empty Password
CVEs:GHSA-jrv5-8w28-4265
Spring Framework Denial of Service via Multipart Requests in WebFlux
CVEs:GHSA-83f7-v6px-pp3h
GHSA-f9p6-prpf-3757
CVEs:GHSA-f9p6-prpf-3757
GHSA-53w6-v7cv-fc9h
CVEs:GHSA-53w6-v7cv-fc9h
GHSA-8h76-qw8h-fmjh
CVEs:GHSA-8h76-qw8h-fmjh
GHSA-gg9r-wr4p-w63h
CVEs:GHSA-gg9r-wr4p-w63h
GHSA-8r2h-xh92-gq57
CVEs:GHSA-8r2h-xh92-gq57
GHSA-9ggw-87m9-9gfc
CVEs:GHSA-9ggw-87m9-9gfc
GHSA-8qq9-r6cc-qjv9
CVEs:GHSA-8qq9-r6cc-qjv9
GHSA-6rpq-6vv2-5222
CVEs:GHSA-6rpq-6vv2-5222
GHSA-x2r2-rvhq-2mqv
CVEs:GHSA-x2r2-rvhq-2mqv
Spring Cloud Function Context: Uncontrolled Recursion is possible while attempting to add infinite amount of functions to Function Registry
CVEs:GHSA-x4h3-g2x4-8gqv
Spring Cloud Function Context has Uncontrolled Recursion
CVEs:GHSA-x9c7-5h6g-hq8q
GHSA-xg2j-3hj6-pc24
CVEs:GHSA-xg2j-3hj6-pc24
GHSA-3pjj-qpw6-5fcm
CVEs:GHSA-3pjj-qpw6-5fcm
GHSA-hw5c-xm3c-v96w
CVEs:GHSA-hw5c-xm3c-v96w
GHSA-2q7c-5gjm-7q23
CVEs:GHSA-2q7c-5gjm-7q23
GHSA-p5mm-xwgq-whfr
CVEs:GHSA-p5mm-xwgq-whfr
Spring Framework Escalation via Session Fixation in WebFlux
CVEs:GHSA-4hfh-6x8g-gwpp
GHSA-mwpv-rg79-863c
CVEs:GHSA-mwpv-rg79-863c
GHSA-m39w-hqxx-3r48
CVEs:GHSA-m39w-hqxx-3r48
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
CVEs:GHSA-cjpg-rgq5-fr37
Spring Framework Arbitrary Method Invocation in SpEL Expressions
CVEs:GHSA-9f52-rjqv-25qv
GHSA-p5f7-rjhp-pxvc
CVEs:GHSA-p5f7-rjhp-pxvc
GHSA-4r8w-73jc-3m7q
CVEs:GHSA-4r8w-73jc-3m7q
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
CVEs:GHSA-pfc9-2cqg-9wq6
Spring Framework Predictable Session ID in WebSocket Module
CVEs:GHSA-q723-847q-5g8g
GHSA-xhf5-x86m-mrgw
CVEs:GHSA-xhf5-x86m-mrgw
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
CVEs:GHSA-vqgp-pf68-6947
Spring Framework Cross-site Scripting via JavaScriptUtils
CVEs:GHSA-3chg-m5w7-qfv5
GHSA-6mfm-98wv-32wm
CVEs:GHSA-6mfm-98wv-32wm
Spring Framework Cross-site Scripting via JSP Form Tags
CVEs:GHSA-957g-f97v-vppc
GHSA-hf28-w9wf-5x8m
CVEs:GHSA-hf28-w9wf-5x8m
GHSA-ww38-37g9-m3q3
CVEs:GHSA-ww38-37g9-m3q3
Spring Framework Open Redirect in Spring MVC and WebFlux
CVEs:GHSA-h3qp-gqrc-q736
GHSA-p8qj-fj6r-w7q9
CVEs:GHSA-p8qj-fj6r-w7q9
GHSA-wx8w-j86h-c458
CVEs:GHSA-wx8w-j86h-c458
GHSA-p7qj-2q5w-f9r7
CVEs:GHSA-p7qj-2q5w-f9r7
GHSA-9wxp-w4px-32vh
CVEs:GHSA-9wxp-w4px-32vh
Spring Framework Server-Side Request Forgery via UriComponentsBuilder
CVEs:GHSA-7m2p-62gw-p8qq
GHSA-gmvv-r68v-m7x9
CVEs:GHSA-gmvv-r68v-m7x9
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
CVEs:GHSA-293q-567p-wmwq
GHSA-96vc-39m3-22w5
CVEs:GHSA-96vc-39m3-22w5
GHSA-cggw-g858-xx4w
CVEs:GHSA-cggw-g858-xx4w
GHSA-ggg2-9786-hwc8
CVEs:GHSA-ggg2-9786-hwc8
GHSA-fqm2-p6px-f54c
CVEs:GHSA-fqm2-p6px-f54c
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.