Known vulnerabilities in Spring Boot
Vendor:
Spring
Software:
Spring Boot
Software CPE:
cpe:2.3:a:spring:spring-boot:*:*:*:*:*:*:*:*
Website:
https://spring.io/
Total vulnerabilities:
18
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.5.16
2.7.34
3.3.20
3.4.17
3.5.14.1
4.0.6.1
4.1.0
4.0.7
3.5.15
3.4.16
3.3.19
2.7.33
4.0.6
3.5.14
2.7.32
3.3.18
3.4.15
2.7.31
3.3.17
3.4.14
4.0.5
3.5.13
4.0.4
3.5.12
4.0.3
3.5.11
4.0.2
3.5.10
4.0.1
3.5.9
3.4.13
4.0.0
3.5.8
3.4.12
3.5.7
3.4.11
3.5.6
3.4.10
3.5.5
3.4.9
3.5.4
3.4.8
3.5.3
3.5.2
3.5.1
3.4.7
3.3.13
3.5.0
3.4.6
3.3.12
2.7.25
3.2.14
3.1.16
2.7.24
2.7.23
3.1.15
3.1.14
3.2.13
3.4.5
3.3.11
3.4.4
3.3.10
3.4.3
3.3.9
3.4.2
3.3.8
3.4.1
3.3.7
3.4.0
3.3.6
3.2.12
3.3.5
3.2.11
3.3.4
3.2.10
2.7.22
2.7.21
2.7.20
2.7.19
3.1.13
3.0.17
3.0.16
3.0.15
3.0.14
3.3.3
3.2.9
3.3.2
3.2.8
3.3.1
3.2.7
3.3.0
3.2.6
3.1.12
3.2.5
3.1.11
3.2.4
3.1.10
3.2.3
3.1.9
3.2.2
3.1.8
3.2.1
3.1.7
3.2.0
3.1.6
3.0.13
2.7.18
3.1.5
3.0.12
2.7.17
3.1.4
3.0.11
2.7.16
3.1.3
3.0.10
2.7.15
3.1.2
3.0.9
2.7.14
3.1.1
3.0.8
2.7.13
3.1.0
2.6.15
2.5.15
3.0.7
2.7.12
3.0.6
2.7.11
3.0.5
2.7.10
3.0.4
3.0.3
2.7.9
3.0.2
2.7.8
3.0.1
2.7.7
3.0.0
2.7.6
2.6.14
2.7.5
2.6.13
2.7.4
2.6.12
2.7.3
2.6.11
2.7.2
2.6.10
2.7.1
2.6.9
2.7.0
2.6.8
2.5.14
2.6.7
2.5.13
2.6.6
2.5.12
2.6.5
2.5.11
2.6.4
2.5.10
2.6.3
2.5.9
2.6.2
2.5.8
2.6.1
2.6.0
2.5.7
2.4.13
2.5.6
2.4.12
2.4.11
2.5.5
2.5.4
2.4.10
2.5.3
2.4.9
2.5.2
2.4.8
2.5.1
2.3.12
2.4.7
2.5.0
2.4.6
2.3.11
2.4.5
2.4.4
2.4.3
2.4.2
2.4.1
2.4.0
2.3.10
2.3.9
2.3.8
2.3.7
2.3.6
2.3.5
2.3.4
2.3.3
2.3.2
2.3.1
2.3.0
2.2.13
2.2.12
2.2.11
2.2.10
2.2.9
2.2.8
2.2.7
2.2.6
2.2.5
2.2.4
2.2.3
2.2.2
2.2.1
2.2.0
2.1.18
2.1.17
2.1.16
2.1.15
2.1.14
2.1.13
2.1.12
2.1.11
2.1.10
2.1.9
2.1.8
2.1.7
2.1.6
2.1.5
2.1.4
2.1.3
2.1.2
2.1.1
2.1.0
2.0.9
2.0.8
2.0.7
2.0.6
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0.0
1.5.22
1.5.21
1.5.20
1.5.19
1.5.18
1.5.17
1.5.16
1.5.15
1.5.14
1.5.13
1.5.12
1.5.11
1.5.10
1.5.9
1.5.8
1.5.7
1.5.6
1.5.5
1.5.4
1.5.3
1.5.2
1.5.1
1.5.0
1.4.7
1.4.6
1.4.5
1.4.4
1.4.3
1.4.2
1.4.1
1.4.0
1.3.8
1.3.7
1.3.6
1.3.5
1.3.4
1.3.3
1.3.2
1.3.1
1.3.0
1.2.8
1.2.7
1.2.6
1.2.5
1.2.4
1.2.3
1.2.2
1.2.1
1.2.0
1.1.12
1.1.11
1.1.10
1.1.9
1.1.8
1.1.7
1.1.6
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.2
1.0.1
1.0.0
Vulnerabilities (18)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU134322 - Improper Certificate Validation CVE-2026-40992 |
CWE-295 | Medium | 3.4.17, 3.5.14.1, 3.5.15, 4.0.6.1, 4.0.7 | 11.06.2026 |
SB2026061136 SB2026073114 |
||
| #VU134321 - Insecure Temporary File CVE-2026-41001 |
CWE-377 | Low | 2.7.34, 3.3.20, 3.4.17, 3.5.14.1, 3.5.15, 4.0.6.1, 4.0.7 | 11.06.2026 |
SB2026061136 SB2026073114 |
||
| #VU128374 - Improper Access Control CVE-2026-22731 |
CWE-284 | High | 3.4.15, 3.5.12, 4.0.4 | 28.04.2026 |
SB20260428205 SB2026061632 SB2026062914 and 1 more |
||
| #VU128371 - Improper Access Control CVE-2026-22733 |
CWE-284 | High | 2.7.32, 3.3.18, 3.4.15, 3.5.12, 4.0.4 | 28.04.2026 |
SB20260428205 SB2026052937 SB2026061632 and 1 more |
||
| #VU128236 - Improper Access Control CVE-2026-40976 |
CWE-284 | High | 4.0.6 | 27.04.2026 |
SB20260427182 |
||
| #VU128235 - Improper Link Resolution Before File Access ('Link Following') CVE-2026-40977 |
CWE-59 | Low | 2.7.33, 3.3.19, 3.4.16, 3.5.14, 4.0.6 | 27.04.2026 |
SB20260427182 SB2026052513 SB2026052929 and 2 more |
||
| #VU128234 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) CVE-2026-40975 |
CWE-338 | Medium | 2.7.33, 3.3.19, 3.4.16, 3.5.14, 4.0.6 | 27.04.2026 |
SB20260427182 SB2026052513 SB2026052929 and 3 more |
||
| #VU128233 - Improper Validation of Certificate with Host Mismatch CVE-2026-40974 |
CWE-297 | Medium | 2.7.33, 3.3.19, 3.4.16, 3.5.14, 4.0.6 | 27.04.2026 |
SB20260427182 SB2026052513 SB20260528266 and 2 more |
||
| #VU128232 - Improper Access Control CVE-2026-40973 |
CWE-284 | Low | 2.7.33, 3.3.19, 3.4.16, 3.5.14, 4.0.6 | 27.04.2026 |
SB20260427182 SB2026052513 SB2026052929 and 2 more |
||
| #VU128231 - Information Exposure Through Timing Discrepancy CVE-2026-40972 |
CWE-208 | Medium | 2.7.33, 3.3.19, 3.4.16, 3.5.14, 4.0.6 | 27.04.2026 |
SB20260427182 SB2026052513 |
||
| #VU128230 - Improper Validation of Certificate with Host Mismatch CVE-2026-40971 |
CWE-297 | Medium | 3.5.14, 4.0.6 | 27.04.2026 |
SB20260427182 SB2026060827 SB2026062914 |
||
| #VU128229 - Improper Certificate Validation CVE-2026-40970 |
CWE-295 | Medium | 4.0.6 | 27.04.2026 |
SB20260427182 |
||
| #VU107966 - Missing Authorization CVE-2025-22235 |
CWE-862 | Medium | 2.7.25, 3.1.16, 3.2.14, 3.3.11, 3.4.5 | 25.04.2025 |
SB2025042526 SB2025060429 SB2025060529 and 15 more |
||
| #VU96484 - Improper Verification of Cryptographic Signature CVE-2024-38807 |
CWE-347 | Low | 2.7.22, 3.0.17, 3.1.13, 3.2.9, 3.3.3 | 23.08.2024 |
SB2024082337 SB2025012192 SB2025012468 and 1 more |
||
| #VU83582 - Improper input validation CVE-2023-34053 |
CWE-20 | Medium | 2.7.18, 3.0.13, 3.1.6 | 29.11.2023 |
SB2023112966 SB2023112967 SB2024011661 and 13 more |
||
| #VU83581 - Improper input validation CVE-2023-34055 |
CWE-20 | Medium | 2.7.18, 3.0.13, 3.1.6 | 29.11.2023 |
SB2023112967 SB2024011660 SB2024011661 and 22 more |
||
| #VU76427 - Resource Management Errors CVE-2023-20883 |
CWE-399 | Medium | 2.5.15, 2.6.15, 2.7.12, 3.0.7 | 23.05.2023 |
SB2023052310 SB2023052311 SB2023061548 and 42 more |
||
| #VU75407 - Security Features CVE-2023-20873 |
CWE-254 | Medium | 2.7.11, 3.0.6 | 21.04.2023 |
SB2023042129 SB2023042132 SB2023060816 and 16 more |