org.springframework:spring-webflux
Maven18 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework:spring-webfluxpage 1 of 1
- CVE-2020-5397MEDIUMCVSS 5.3EG 5.3✓ Fixed in 5.2.32020-01-17
vulnerable: 5.2.0.RELEASE, 5.2.1.RELEASE, 5.2.2.RELEASE
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoi…
- CVE-2020-5398CRITICALCVSS 7.5EG 9.0✓ Fixed in 5.0.16.RELEASE2020-01-17
vulnerable: 5.0.0.RELEASE ... 5.0.9.RELEASE (16 versions)
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in t…
- CVE-2022-22965CRITICALCVSS 9.8EG 9.8⚠ KEV✓ Fixed in 5.3.182022-04-01
vulnerable: 5.3.0 ... 5.3.9 (18 versions)
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deplo…
- CVE-2024-38816HIGHCVSS 7.5EG 7.5✓ Fixed in 6.1.132024-09-13
vulnerable: 5.3.0 ... 5.3.9 (40 versions)
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also…
- CVE-2024-38819HIGHCVSS 7.5EG 8.2✓ Fixed in 6.1.142024-12-19
vulnerable: 6.0.0 ... 6.0.9 (24 versions)
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also…
- CVE-2026-22735LOWCVSS 2.6EG 2.6✓ Fixed in 6.2.172026-03-20
vulnerable: 5.3.0 ... 5.3.9 (40 versions)
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 …
- CVE-2026-22737MEDIUMCVSS 5.9EG 5.9✓ Fixed in 6.2.172026-03-20
vulnerable: 5.3.0 ... 5.3.9 (40 versions)
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue a…
- CVE-2026-22740MEDIUMCVSS 6.5EG 6.5✓ Fixed in 6.2.182026-04-29
vulnerable: 5.0.0.RELEASE ... 5.3.9 (108 versions)
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to cons…
- CVE-2026-22741LOWCVSS 3.1EG 3.1✓ Fixed in 6.2.182026-04-29
vulnerable: 5.0.0.RELEASE ... 5.3.9 (108 versions)
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring …
- CVE-2026-22745MEDIUMCVSS 5.3EG 5.3✓ Fixed in 6.2.182026-04-29
vulnerable: 5.0.0.RELEASE ... 5.3.9 (108 versions)
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC …
- CVE-2026-41839MEDIUMCVSS 4.2EG 4.2✓ Fixed in 6.2.192026-06-09
vulnerable: 5.0.0.RELEASE ... 5.3.9 (108 versions)
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring …
- CVE-2026-41840MEDIUMCVSS 5.9EG 5.9✓ Fixed in 6.2.192026-06-09
vulnerable: 5.0.0.RELEASE ... 5.3.9 (108 versions)
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
- CVE-2026-41841MEDIUMCVSS 5.9EG 5.9✓ Fixed in 6.2.192026-06-09
vulnerable: 5.0.0.RELEASE ... 5.3.9 (108 versions)
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.4…
- CVE-2026-41842HIGHCVSS 7.5EG 7.5✓ Fixed in 6.2.192026-06-09
vulnerable: 5.0.0.RELEASE ... 5.3.9 (108 versions)
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.…
- CVE-2026-41843MEDIUMCVSS 5.9EG 5.9✓ Fixed in 6.2.192026-06-09
vulnerable: 5.0.0.RELEASE ... 5.3.9 (108 versions)
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
- CVE-2026-41844MEDIUMCVSS 6.1EG 6.1✓ Fixed in 6.2.192026-06-09
vulnerable: 5.0.0.RELEASE ... 5.3.9 (108 versions)
A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: …
- CVE-2026-41847MEDIUMCVSS 5.3EG 5.32026-06-09
vulnerable: 5.0.0.RELEASE ... 5.3.9 (108 versions)
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.
- CVE-2026-41853MEDIUMCVSS 5.3EG 5.3✓ Fixed in 6.2.192026-06-09
vulnerable: 5.0.0.RELEASE ... 5.3.9 (108 versions)
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Check whether org.springframework:spring-webflux is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework:spring-webflux CVEs against the assets you own.
Start Free Scan →