CVE-2026-59328
Last modified
CVE-2026-59328 is a medium-severity vulnerability rated 4.2/10 on the CVSS scale. Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard.
Description
Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Spring | Spring Tools for Eclipse | <= 5.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-59328?
How severe is CVE-2026-59328?
How do I fix CVE-2026-59328?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59321A single ScriptEngine instance is reused for every message o…5.4
- CVE-2026-59322The EmbeddedHeadersJsonMessageMapper defaults to an overly p…6.3
- CVE-2026-59323An application using Micrometer Tracing with W3C baggage pro…5.3
- CVE-2026-59324When an IntegrationFlow uses .fluxTransform() with an asynch…8.2
- CVE-2026-59326The Spring Boot language server logs the raw value of the ht…3.3
- CVE-2026-59327Spring Tools for Eclipse stores the Spring Boot DevTools rem…4.4
- CVE-2026-59335Improper handling of case sensitivity (CWE-178) in the ident…8.7
- CVE-2026-5934The WP Rocket plugin for WordPress is vulnerable to Stored C…7.2
- CVE-2026-59341A security vulnerability exists in the Sealed Secrets contro…4.2
- CVE-2026-5935IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9…9.8
- CVE-2026-59354In versions of Spring Security's OAuth2 Authorization Server…8.8
- CVE-2026-59355In versions of Spring Authorization Server 1.5.0 through 1.5…6.1
Are you affected by CVE-2026-59328?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
