VulnSea

springframework has 4 CVEs on record. The busiest recent month was June 2026 with 4. The median CVSS is 7.4 (high). Most affected products: org.springframework.kafka:spring-kafka (2), org.springframework.security:spring-security-web (1), org.springframework:spring-jms (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.4
Publish → KEV
Last 90 days
0 prev 4

Products

  • org.springframework.kafka:spring-kafka 2
  • org.springframework.security:spring-security-web 1
  • org.springframework:spring-jms 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

springframework vulnerabilities

CVEs affecting springframework, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-41731High· 8.1
3mo ago

In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization

In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization

Twilightspringframework · org.springframework.kafka:spring-kafkaEPSS 0.51%via GHSA
CVE-2026-41726Medium· 6.5
3mo ago

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

Sunlitspringframework · org.springframework.kafka:spring-kafkaEPSS 0.30%via GHSA
CVE-2026-47838Medium· 6.8
3mo ago

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

Sunlitspringframework · org.springframework.security:spring-security-webEPSS 0.13%via GHSA
CVE-2026-41855High· 8.1
3mo ago

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…

Twilightspringframework · org.springframework:spring-jmsEPSS 0.29%via NVD
springframework vulnerabilities (CVEs) · VulnSea