CVE Tools

Spring Boot

24 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Spring Boot, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Spring Boot CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Spring Boot CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-032
2026-048
2026-050
2026-062
2026-070
2026-080
2026-090

Severity

How the 24 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical417%
  • High938%
  • Medium1042%
  • Low14%

Latest CVEs

The 15 most recently published vulnerabilities affecting Spring Boot.

  1. CVE-2026-41001Predictable Temp Directory in Artemis Auto-configuration5.3
  2. CVE-2026-40992Mail Auto-Configuration Does Not Enable SSL Hostname Verification5.0
  3. CVE-2026-40977When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is star...4.7
  4. CVE-2026-40976In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web appli...9.1
  5. CVE-2026-40975Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values ...4.8
  6. CVE-2026-40974Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 ...5.0
  7. CVE-2026-40973A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack...7.0
  8. CVE-2026-40972An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the a...7.5
  9. CVE-2026-40971When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (...5.0
  10. CVE-2026-40970When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0...5.0
  11. CVE-2026-22733Authentication Bypass under Actuator CloudFoundry endpoints8.2
  12. CVE-2026-22731Authentication Bypass under Actuator Health groups paths8.2
  13. CVE-2025-22235Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed7.3
  14. CVE-2024-38807CVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's Loader6.3
  15. CVE-2024-22233CVE-2024-22233: Spring Framework server Web DoS Vulnerability7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store