Software catalogue for Spring
Latest security bulletins
| Secuity bulletin | Severity | Status | Published |
|---|---|---|---|
| SB2026011393: Remote command execution in Spring CLI VSCode Extension | High | 13.01.2026 | |
| SB2025042526: Missing authorization in Spring Boot | Medium | 25.04.2025 | |
| SB2024082337: Digital signature forgery in Spring Boot Loader | Low | 23.08.2024 | |
| SB2024032029: PKCE downgrade in Spring Authorization Server | Medium | 20.03.2024 | |
| SB2024020212: Local information disclosure in Spring Cloud Contract | Low | 02.02.2024 | |
| SB2023112967: Multiple DoS vulnerabilities in Spring Boot server Web Observations | Medium | 29.11.2023 | |
| SB2023112073: Spring for Apache Kafka update for ZooKeeper | Medium | 20.11.2023 | |
| SB2023082369: Remote code execution in Spring for Apache Kafka | Medium | 23.08.2023 | |
| SB2023053138: Remote code execution in Spring Tools 4 extensions for Eclipse and VSCode | High | 31.05.2023 | |
| SB2023052310: Denial of service in Spring Boot welcome page | Medium | 23.05.2023 |