Spring Boot
24 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Spring Boot, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Spring Boot CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 2 |
| 2026-04 | 8 |
| 2026-05 | 0 |
| 2026-06 | 2 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 24 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High9
- Medium10
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Spring Boot.
- CVE-2026-41001Predictable Temp Directory in Artemis Auto-configuration5.3
- CVE-2026-40992Mail Auto-Configuration Does Not Enable SSL Hostname Verification5.0
- CVE-2026-40977When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is star...4.7
- CVE-2026-40976In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web appli...9.1
- CVE-2026-40975Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values ...4.8
- CVE-2026-40974Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 ...5.0
- CVE-2026-40973A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack...7.0
- CVE-2026-40972An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the a...7.5
- CVE-2026-40971When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (...5.0
- CVE-2026-40970When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0...5.0
- CVE-2026-22733Authentication Bypass under Actuator CloudFoundry endpoints8.2
- CVE-2026-22731Authentication Bypass under Actuator Health groups paths8.2
- CVE-2025-22235Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed7.3
- CVE-2024-38807CVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's Loader6.3
- CVE-2024-22233CVE-2024-22233: Spring Framework server Web DoS Vulnerability7.5
Product grouping is registry-driven, with AI assist and human review. How it works