CVE-2026-47873
Last modified
CVE-2026-47873 is a high-severity vulnerability rated 8/10 on the CVSS scale. The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Spring | Spring Tools for Eclipse | <= 5.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-47873?
How severe is CVE-2026-47873?
How do I fix CVE-2026-47873?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-47866VMware Avi Load Balancer contains an authorization bypass vu…8.3
- CVE-2026-47867VMware Avi Load Balancer contains a remote code execution vu…8.8
- CVE-2026-47868VMware Avi Load Balancer contains a local privilege escalati…7.8
- CVE-2026-47869VMware Avi Load Balancer contains a remote code execution vu…8.8
- CVE-2026-47870VMware Avi Load Balancer contains a privilege escalation vul…8.8
- CVE-2026-47871VMware Avi Load Balancer contains a directory traversal vuln…8.8
- CVE-2026-47874The vulnerability occurs when a client sends HTTP/1.1 pipeli…5.3
- CVE-2026-47875Applications that deserialize execution contexts with Jackso…9.8
- CVE-2026-47876VMware ESX contains an out-of-bounds write vulnerability in …9.3
- CVE-2026-47877Spring Security Authorization Server's default consent page …6.1
- CVE-2026-47878DefaultExecutionContextSerializer, used by default in Spring…7.3
- CVE-2026-47879Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows a…8.7
Are you affected by CVE-2026-47873?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
