springframework has 4 CVEs on record. The busiest recent month was June 2026 with 4. The median CVSS is 7.4 (high). Most affected products: org.springframework.kafka:spring-kafka (2), org.springframework.security:spring-security-web (1), org.springframework:spring-jms (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.4
- Publish → KEV
- —
- Last 90 days
- 0 prev 4
Products
- org.springframework.kafka:spring-kafka 2
- org.springframework.security:spring-security-web 1
- org.springframework:spring-jms 1
Worst active — by depth score
CVE-2026-41731High· 8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization45CVE-2026-41855High· 8.1In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…45CVE-2026-47838Medium· 6.8Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates37CVE-2026-41726Medium· 6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header36
springframework vulnerabilities
CVEs affecting springframework, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-41731High· 8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
CVE-2026-41726Medium· 6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
CVE-2026-47838Medium· 6.8Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
CVE-2026-41855High· 8.1In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…