Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18. Join the discussion | CVE Database V5 | 06/09/2026, 06:31:58 UTC Added: 06/09/2026, 04:48:50 UTC |
0 In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. Join the discussion | CVE Database V5 | 06/09/2026, 03:51:57 UTC Added: 06/09/2026, 04:48:54 UTC |
0 Spring Framework versions 5.3.0 through 5.3.48, 6.1.0 through 6.1.27, 6.2.0 through 6.2.18, and 7.0.0 through 7.0.7 are vulnerable to HTTP request smuggling attacks via multipart requests. This vulnerability is identified as CWE-444, involving inconsistent interpretation of HTTP requests. The CVSS score is 5.3, indicating a medium severity level. No official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 06/09/2026, 03:51:44 UTC Added: 06/09/2026, 04:48:50 UTC |
CVE-2026-41852 is a vulnerability in the Spring Framework's Spring Expression Language (SpEL) evaluation logic that allows arbitrary zero-argument method invocation even in restricted or read-only contexts. This could enable attackers to invoke unintended application logic. The affected versions include Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48. The vulnerability has a low severity rating and a CVSS score of 3.7. No official patch or remediation guidance is currently provided. Join the discussion | CVE Database V5 | 06/09/2026, 03:51:39 UTC Added: 06/09/2026, 04:48:50 UTC |
0 Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. Join the discussion | CVE Database V5 | 06/09/2026, 03:51:32 UTC Added: 06/09/2026, 04:48:50 UTC |
0 Spring Framework versions 5.3.0 through 5.3.48, 6.1.0 through 6.1.27, 6.2.0 through 6.2.18, and 7.0.0 through 7.0.7 are affected by an inefficient algorithmic complexity vulnerability in the evaluation of Spring Expression Language (SpEL) expressions. This vulnerability allows an attacker to supply specially crafted expressions that cause excessive resource consumption, potentially leading to denial of service conditions. The vulnerability is identified as CWE-407 and has a CVSS v3.1 score of 7.5, indicating high severity. No official patch or remediation guidance is currently provided by the vendor. Join the discussion | CVE Database V5 | 06/09/2026, 03:51:22 UTC Added: 06/09/2026, 04:48:50 UTC |
CVE-2026-41849 is an integer overflow vulnerability in the Spring Expression Language (SpEL) evaluation logic of the Spring Framework. This flaw allows an attacker to craft a SpEL expression that triggers excessive resource consumption, resulting in a denial of service (DoS). It affects Spring Framework versions 5.3.0 through 5.3.48. The vulnerability has a high severity score of 7.5. Currently, no official patch or remediation guidance is available from the vendor. Join the discussion | CVE Database V5 | 06/09/2026, 03:51:17 UTC Added: 06/09/2026, 04:48:50 UTC |
0 A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Spring Framework's AntPathMatcher component. This affects versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48. The vulnerability arises when an attacker can supply a crafted pattern to certain AntPathMatcher methods, potentially causing inefficient regular expression processing and denial of service. The CVSS score is 3.7, indicating low severity. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 06/09/2026, 03:51:12 UTC Added: 06/09/2026, 04:48:50 UTC |
CVE-2026-41847 is a medium severity vulnerability in the Spring Framework's WebFlux Kotlin Router DSL that allows improper access control, potentially enabling security bypass. It affects Spring Framework versions from 5.3.0 through 5.3.48. There is currently no official patch or remediation guidance from the vendor. No known exploits are reported in the wild at this time. Join the discussion | CVE Database V5 | 06/09/2026, 03:51:03 UTC Added: 06/09/2026, 04:48:50 UTC |
0 A cross-site scripting (XSS) vulnerability exists in Spring Framework's MVC component where user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags are not properly neutralized. This allows injection of arbitrary HTML or JavaScript code. The vulnerability affects multiple versions of Spring Framework including 5.3.0 through 5.3.48, 6.1.0 through 6.1.27, 6.2.0 through 6.2.18, and 7.0.0 through 7.0.7. The CVSS score is 5.9, indicating a medium severity level. No official patch or remediation guidance is currently provided by the vendor. Join the discussion | CVE Database V5 | 06/09/2026, 03:50:56 UTC Added: 06/09/2026, 04:48:50 UTC |
Showing 1 to 10 of 23 results