2026 CVE Vulnerabilities
61,555 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41855 | CRITICAL | 9.8 | 0.3% | Jun 9, 2026 | In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sprin... |
| CVE-2026-41854 | MEDIUM | 6.5 | 0.1% | Jun 9, 2026 | Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provid... |
| CVE-2026-41853 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Fr... |
| CVE-2026-41852 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocati... |
| CVE-2026-41851 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of S... |
| CVE-2026-41850 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic ... |
| CVE-2026-41849 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker c... |
| CVE-2026-41848 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provid... |
| CVE-2026-41847 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions:... |
| CVE-2026-41846 | MEDIUM | 6.1 | 0.1% | Jun 9, 2026 | Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP ... |
| CVE-2026-41845 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the br... |
| CVE-2026-41844 | MEDIUM | 6.1 | 0.1% | Jun 9, 2026 | A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly sp... |
| CVE-2026-41843 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected ... |
| CVE-2026-41842 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. ... |
| CVE-2026-41841 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A... |
| CVE-2026-41840 | MEDIUM | 5.9 | 0.2% | Jun 9, 2026 | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect... |
| CVE-2026-41839 | MEDIUM | 4.2 | 0.2% | Jun 9, 2026 | A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab... |
| CVE-2026-41838 | HIGH | 7.5 | 0.2% | Jun 9, 2026 | IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible... |
| CVE-2026-41720 | HIGH | 7.4 | 0.3% | Jun 9, 2026 | Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username i... |
| CVE-2026-41715 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may ... |
| CVE-2026-41710 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the applicati... |
| CVE-2026-41007 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. ... |
| CVE-2026-41006 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media ty... |
| CVE-2026-40984 | HIGH | 7.5 | 0.8% | Jun 9, 2026 | In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (... |
| CVE-2026-40983 | HIGH | 7.5 | 0.6% | Jun 9, 2026 | In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now