VDB
CVE-2026-22738
CVE-2026-22738
PUBLISHED
Between March 23 and 26, 2026, Spring published security advisories to address vulnerabilities in the following products: Spring Cloud Config – versions prior to 3.1.3, 4.1.9, 4.2.6, 4.3.2 and 5.0.2 Spring AI – versions prior to 1.0.5 and 1.1.4 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
EPSS 1.09% · 62.2th percentile
Risk Scores
EPSS Score
1.09%
62.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| VMware | Spring Cloud Config – versions prior to 3.1.3, 4.1.9, 4.2.6, 4.3.2 and 5.0.2 | |
| VMware | Spring AI – versions prior to 1.0.5 and 1.1.4 |
Timeline
- Mar 26, 2026 CVE Published
- Mar 26, 2026 PoC Published
- Mar 27, 2026 Coalition ESS Score
- Mar 27, 2026 PoC Published
- Mar 27, 2026 PoC Published
- Mar 27, 2026 PoC Published
- Mar 27, 2026 PoC Published
- Mar 27, 2026 PoC Published
- Mar 27, 2026 PoC Published
- Mar 27, 2026 PoC Published
- Mar 27, 2026 PoC Published
- Mar 27, 2026 PoC Published
References
- https://cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-288 advisory
- https://spring.io/security/cve-2026-22739 vendor
- https://spring.io/security/cve-2026-22743 vendor
- https://spring.io/security/cve-2026-22744 vendor
- https://spring.io/security/cve-2026-22742 vendor
- https://spring.io/security/cve-2026-22738 vendor
- https://spring.io/security vendor