Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5 CVE-2026-11850

Krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds read_CVE-2026-11850

An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The fu...

Red Hat Red Hat Enterprise Linux 10 CVE
MEDIUM 6.6 CVE-2025-7064

Freelance Security Lock – Access to Windows OS_CVE-2025-7064

Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 20...

ABB Freelance CVE
HIGH 7.5 CVE-2026-41856

Spring GraphQL Annotation Detection Vulnerability_CVE-2026-41856

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierar...

Spring Spring for GraphQL 2.0.0 CVE
HIGH 8.1 CVE-2026-41700

Cross-Site WebSocket Hijacking in Spring for GraphQL_CVE-2026-41700

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick a...

Spring Spring for GraphQL 2.0.0 CVE
HIGH 8.1 CVE-2026-41699

Unsafe Deserialization in Spring GraphQL_CVE-2026-41699

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicio...

Spring Spring for GraphQL 2.0.0 CVE
MEDIUM 5.3 CVE-2026-41001

Predictable Temp Directory in Artemis Auto-configuration_CVE-2026-41001

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explic...

Spring Spring Boot 4.0.0 CVE
LOW 3.7 CVE-2026-41000

WSS4J validation does not use configured replay cache_CVE-2026-41000

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, pro...

Spring Spring Web Services 5.0.0 CVE
HIGH 8.6 CVE-2026-40999

Spring WS SSRF via unvalidated WS-Addressing reply destinations_CVE-2026-40999

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServi...

Spring Spring Web Services 5.0.0 CVE
HIGH 8.2 CVE-2026-40998

Jaxp13 XPath XXE via StreamSource and SAXSource_CVE-2026-40998

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with th...

Spring Spring Web Services 5.0.0 CVE
MEDIUM 5.3 CVE-2026-40997

SOAP security faults leak Spring Security account state_CVE-2026-40997

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to re...

Spring Spring Web Services 5.0.0 CVE