org.springframework:spring-webmvc
Maven25 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework:spring-webmvcpage 1 of 1
- CVE-2014-0054MEDIUMCVSS v2 6.8EG 6.8fixed in 3.2.8 or 4.0.2, by version range2014-04-17
vulnerable: 4.0.0.RELEASE, 4.0.1.RELEASE
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, a…
- CVE-2014-0225HIGHCVSS 8.8EG 8.8fixed in 4.0.5 or 3.2.8, by version range2017-05-25
vulnerable: 3.0.0.RELEASE ... 3.2.7.RELEASE (21 versions)
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an X…
- CVE-2014-1904MEDIUMCVSS v2 4.3EG 4.3fixed in 3.2.8.RELEASE or 4.0.2.RELEASE, by version range2014-03-20
vulnerable: 4.0.0.RELEASE, 4.0.1.RELEASE
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI…
- CVE-2014-3625MEDIUMCVSS v2 5.0EG 5.0fixed in 3.2.12, 4.0.8 or 4.1.2, by version range2014-11-20
vulnerable: 4.1.0.RELEASE, 4.1.1.RELEASE
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource…
- CVE-2016-9878HIGHCVSS 7.5EG 7.5fixed in 3.2.18, 4.2.9 or 4.3.5, by version range2016-12-29
vulnerable: 4.3.0.RELEASE, 4.3.1.RELEASE, 4.3.2.RELEASE, 4.3.3.RELEASE, 4.3.4.RELEASE
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
- CVE-2020-5397MEDIUMCVSS 5.3EG 5.3fixed in 5.2.32020-01-17
vulnerable: 5.2.0.RELEASE, 5.2.1.RELEASE, 5.2.2.RELEASE
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoi…
- CVE-2020-5398CRITICALCVSS 7.5EG 9.0fixed in 5.2.3.RELEASE, 5.1.13.RELEASE or 5.0.16.RELEASE, by version range2020-01-17
vulnerable: 5.0.0.RELEASE ... 5.0.9.RELEASE (16 versions)
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in t…
- CVE-2022-22965CRITICALCVSS 9.8EG 9.8⚠ KEVfixed in 5.2.20.RELEASE or 5.3.18, by version range2022-04-01
vulnerable: 5.3.0 ... 5.3.9 (18 versions)
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deplo…
- CVE-2023-20860HIGHCVSS 7.5EG 7.5fixed in 6.0.7 or 5.3.26, by version range2023-03-27
vulnerable: 5.3.0 ... 5.3.9 (26 versions)
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the pot…
- CVE-2023-34053MEDIUMCVSS 5.3EG 5.3fixed in 6.0.142023-11-28
vulnerable: 6.0.0 ... 6.0.9 (14 versions)
In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are…
- CVE-2024-38816HIGHCVSS 7.5EG 7.5fixed in 6.1.132024-09-13
vulnerable: 5.3.0 ... 5.3.9 (40 versions)
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also…
- CVE-2024-38819HIGHCVSS 7.5EG 8.2fixed in 6.1.142024-12-19
vulnerable: 6.0.0 ... 6.0.9 (24 versions)
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also…
- CVE-2024-38828MEDIUMCVSS 5.3EG 5.3fixed in 5.3.422024-11-18
vulnerable: 5.3.0 ... 5.3.9 (40 versions)
Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.
- CVE-2025-41242MEDIUMCVSS 5.9EG 5.9fixed in 6.2.102025-08-18
vulnerable: 5.3.0 ... 5.3.9 (40 versions)
Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when all the following are true: * the application is dep…
- CVE-2026-22735LOWCVSS 2.6EG 2.6fixed in 7.0.6 or 6.2.17, by version range2026-03-20
vulnerable: 5.3.0 ... 5.3.9 (40 versions)
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 …
- CVE-2026-22737MEDIUMCVSS 5.9EG 5.9fixed in 7.0.6 or 6.2.17, by version range2026-03-20
vulnerable: 5.3.0 ... 5.3.9 (40 versions)
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue a…
- CVE-2026-22741LOWCVSS 3.1EG 3.1fixed in 7.0.7 or 6.2.18, by version range2026-04-29
vulnerable: 1.0 ... 5.3.9 (250 versions)
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring …
- CVE-2026-22745MEDIUMCVSS 5.3EG 5.3fixed in 7.0.7 or 6.2.18, by version range2026-04-29
vulnerable: 1.0 ... 5.3.9 (250 versions)
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC …
- CVE-2026-41841MEDIUMCVSS 5.9EG 5.9fixed in 7.0.8 or 6.2.19, by version range2026-06-09
vulnerable: 1.0 ... 5.3.9 (250 versions)
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.4…
- CVE-2026-41842HIGHCVSS 7.5EG 7.5fixed in 7.0.8 or 6.2.19, by version range2026-06-09
vulnerable: 1.0 ... 5.3.9 (250 versions)
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.…
- CVE-2026-41843MEDIUMCVSS 5.9EG 5.9fixed in 7.0.8 or 6.2.19, by version range2026-06-09
vulnerable: 1.0 ... 5.3.9 (250 versions)
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
- CVE-2026-41844MEDIUMCVSS 6.1EG 6.1fixed in 7.0.8 or 6.2.19, by version range2026-06-09
vulnerable: 1.0 ... 5.3.9 (250 versions)
A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: …
- CVE-2026-41845HIGHCVSS 6.1EG 7.1fixed in 7.0.8 or 6.2.19, by version range2026-06-09
vulnerable: 1.0 ... 5.3.9 (250 versions)
Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 …
- CVE-2026-41846MEDIUMCVSS 6.1EG 6.1fixed in 7.0.8 or 6.2.19, by version range2026-06-09
vulnerable: 1.0 ... 5.3.9 (250 versions)
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnera…
- CVE-2026-41853MEDIUMCVSS 5.3EG 5.3fixed in 7.0.8 or 6.2.19, by version range2026-06-09
vulnerable: 1.0 ... 5.3.9 (250 versions)
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Check whether org.springframework:spring-webmvc is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework:spring-webmvc CVEs against the assets you own.
Book a Demo →