Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-41856

Spring GraphQL Annotation Detection Vulnerability_CVE-2026-41856

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierar...

Spring Spring for GraphQL 2.0.0 CVE
HIGH 8.1 CVE-2026-41700

Cross-Site WebSocket Hijacking in Spring for GraphQL_CVE-2026-41700

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick a...

Spring Spring for GraphQL 2.0.0 CVE
HIGH 8.1 CVE-2026-41699

Unsafe Deserialization in Spring GraphQL_CVE-2026-41699

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicio...

Spring Spring for GraphQL 2.0.0 CVE
MEDIUM 5.3 CVE-2026-41001

Predictable Temp Directory in Artemis Auto-configuration_CVE-2026-41001

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explic...

Spring Spring Boot 4.0.0 CVE
LOW 3.7 CVE-2026-41000

WSS4J validation does not use configured replay cache_CVE-2026-41000

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, pro...

Spring Spring Web Services 5.0.0 CVE
HIGH 8.6 CVE-2026-40999

Spring WS SSRF via unvalidated WS-Addressing reply destinations_CVE-2026-40999

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServi...

Spring Spring Web Services 5.0.0 CVE
HIGH 8.2 CVE-2026-40998

Jaxp13 XPath XXE via StreamSource and SAXSource_CVE-2026-40998

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with th...

Spring Spring Web Services 5.0.0 CVE
MEDIUM 5.3 CVE-2026-40997

SOAP security faults leak Spring Security account state_CVE-2026-40997

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to re...

Spring Spring Web Services 5.0.0 CVE
MEDIUM 4.8 CVE-2026-40996

Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default_CVE-2026-40996

Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inb...

Spring Spring Web Services 5.0.0 CVE
MEDIUM 5.4 CVE-2026-40995

X.509 authentication bypasses Spring Security account checks_CVE-2026-40995

X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without ap...

Spring Spring Web Services 5.0.0 CVE