2026 CVE Vulnerabilities

61,555 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41855CRITICAL9.8In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sprin...
CVE-2026-41854MEDIUM6.5Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provid...
CVE-2026-41853MEDIUM5.3Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Fr...
CVE-2026-41852MEDIUM5.3A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocati...
CVE-2026-41851HIGH7.5Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of S...
CVE-2026-41850HIGH7.5Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic ...
CVE-2026-41849HIGH7.5An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker c...
CVE-2026-41848HIGH7.5Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provid...
CVE-2026-41847MEDIUM5.3Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions:...
CVE-2026-41846MEDIUM6.1Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP ...
CVE-2026-41845MEDIUM6.1Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the br...
CVE-2026-41844MEDIUM6.1A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly sp...
CVE-2026-41843MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected ...
CVE-2026-41842HIGH7.5Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. ...
CVE-2026-41841MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A...
CVE-2026-41840MEDIUM5.9Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect...
CVE-2026-41839MEDIUM4.2A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab...
CVE-2026-41838HIGH7.5IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible...
CVE-2026-41720HIGH7.4Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username i...
CVE-2026-41715MEDIUM6.1In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may ...
CVE-2026-41710MEDIUM5.9An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the applicati...
CVE-2026-41007HIGH7.5Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. ...
CVE-2026-41006HIGH7.5Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media ty...
CVE-2026-40984HIGH7.5In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (...
CVE-2026-40983HIGH7.5In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now