Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/org.springframework/spring-framework

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.

Join the discussion

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Join the discussion

Spring Framework versions 5.3.0 through 5.3.48, 6.1.0 through 6.1.27, 6.2.0 through 6.2.18, and 7.0.0 through 7.0.7 are vulnerable to HTTP request smuggling attacks via multipart requests. This vulnerability is identified as CWE-444, involving inconsistent interpretation of HTTP requests. The CVSS score is 5.3, indicating a medium severity level. No official patch or remediation guidance has been provided yet.

Join the discussion

CVE-2026-41852 is a vulnerability in the Spring Framework's Spring Expression Language (SpEL) evaluation logic that allows arbitrary zero-argument method invocation even in restricted or read-only contexts. This could enable attackers to invoke unintended application logic. The affected versions include Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48. The vulnerability has a low severity rating and a CVSS score of 3.7. No official patch or remediation guidance is currently provided.

Join the discussion

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Join the discussion

Spring Framework versions 5.3.0 through 5.3.48, 6.1.0 through 6.1.27, 6.2.0 through 6.2.18, and 7.0.0 through 7.0.7 are affected by an inefficient algorithmic complexity vulnerability in the evaluation of Spring Expression Language (SpEL) expressions. This vulnerability allows an attacker to supply specially crafted expressions that cause excessive resource consumption, potentially leading to denial of service conditions. The vulnerability is identified as CWE-407 and has a CVSS v3.1 score of 7.5, indicating high severity. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion

CVE-2026-41849 is an integer overflow vulnerability in the Spring Expression Language (SpEL) evaluation logic of the Spring Framework. This flaw allows an attacker to craft a SpEL expression that triggers excessive resource consumption, resulting in a denial of service (DoS). It affects Spring Framework versions 5.3.0 through 5.3.48. The vulnerability has a high severity score of 7.5. Currently, no official patch or remediation guidance is available from the vendor.

Join the discussion

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Spring Framework's AntPathMatcher component. This affects versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48. The vulnerability arises when an attacker can supply a crafted pattern to certain AntPathMatcher methods, potentially causing inefficient regular expression processing and denial of service. The CVSS score is 3.7, indicating low severity. No official patch or remediation guidance is currently available.

Join the discussion

CVE-2026-41847 is a medium severity vulnerability in the Spring Framework's WebFlux Kotlin Router DSL that allows improper access control, potentially enabling security bypass. It affects Spring Framework versions from 5.3.0 through 5.3.48. There is currently no official patch or remediation guidance from the vendor. No known exploits are reported in the wild at this time.

Join the discussion

A cross-site scripting (XSS) vulnerability exists in Spring Framework's MVC component where user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags are not properly neutralized. This allows injection of arbitrary HTML or JavaScript code. The vulnerability affects multiple versions of Spring Framework including 5.3.0 through 5.3.48, 6.1.0 through 6.1.27, 6.2.0 through 6.2.18, and 7.0.0 through 7.0.7. The CVSS score is 5.9, indicating a medium severity level. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion

Showing 1 to 10 of 23 results

Filters:Package: pkg:maven/org.springframework/spring-framework
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses