Known vulnerabilities in Spring Framework 7.0.0-M8

Vendor: Broadcom
Version: 7.0.0-M8
Software CPE: cpe:2.3:a:broadcom:pivotal_spring_framework:*:*:*:*:*:*:*:*
Total vulnerabilities: 5
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Spring Framework version 7.0.0-M8 Spring Framework 7.0.0-M8 is affected by 5 vulnerabilities: 2 medium, 3 low Critical High Medium Low

Vulnerabilities (5)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU128385 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-22735
CWE-74 Low
No
No
5.3.47, 6.1.26, 6.2.17, 7.0.6 28.04.2026 SB20260428206
SB2026043058
SB2026052217
and 4 more
#VU128372 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-22737
CWE-22 Medium
No
No
5.3.47, 6.1.26, 6.2.17, 7.0.6 28.04.2026 SB20260428206
SB2026043058
SB2026052218
and 4 more
#VU126710 - Resource exhaustion
CVE-2026-22745
CWE-400 Medium
No
No
5.3.48, 6.1.27, 6.2.18, 7.0.7 21.04.2026 SB2026042162
SB2026052514
SB2026060904
and 2 more
#VU126709 - Acceptance of Extraneous Untrusted Data With Trusted Data
CVE-2026-22741
CWE-349 Low
No
No
5.3.48, 6.1.27, 6.2.18, 7.0.7 21.04.2026 SB2026042162
SB2026052514
SB20260528259
and 2 more
#VU126708 - Improper Resource Shutdown or Release
CVE-2026-22740
CWE-404 Low
No
No
5.3.48, 6.1.27, 6.2.18, 7.0.7 21.04.2026 SB2026042162
SB2026052514
SB2026060812