---
id: CVE-2026-47873
title: >-
  The Boot Dashboard Docker integration in Spring Tools publishes container
  control ports on all of the host's network interfaces (0.0.0.0) rather than
  restricting them to loopback.

  Affected Spring Products and Versions:

  Spring Tools for E…
summary: >-
  The Boot Dashboard Docker integration in Spring Tools publishes container
  control ports on all of the host's network interfaces (0.0.0.0) rather than
  restricting them to loopback.

  Affected Spring Products and Versions:

  Spring Tools for E…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-1327
published: '2026-07-30'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47873'
references:
  - url: 'https://spring.io/security/cve-2026-47873'
    label: security@vmware.com
tags:
  - nvd
epss: 0.00286
epssPercentile: 0.18885
ingestedAt: '2026-08-01T21:14:39.709Z'
---

## Overview

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
