2026 CVE Vulnerabilities

61,653 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41853MEDIUM5.3Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Fr...
CVE-2026-41852MEDIUM5.3A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocati...
CVE-2026-41851HIGH7.5Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of S...
CVE-2026-41850HIGH7.5Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic ...
CVE-2026-41849HIGH7.5An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker c...
CVE-2026-41848HIGH7.5Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provid...
CVE-2026-41847MEDIUM5.3Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions:...
CVE-2026-41846MEDIUM6.1Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP ...
CVE-2026-41845MEDIUM6.1Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the br...
CVE-2026-41844MEDIUM6.1A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly sp...
CVE-2026-41843MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected ...
CVE-2026-41842HIGH7.5Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. ...
CVE-2026-41841MEDIUM5.9Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A...
CVE-2026-41840MEDIUM5.9Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect...
CVE-2026-41839MEDIUM4.2A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab...
CVE-2026-41838HIGH7.5IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible...
CVE-2026-41720HIGH7.4Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username i...
CVE-2026-41715MEDIUM6.1In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may ...
CVE-2026-41710MEDIUM5.9An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the applicati...
CVE-2026-41007HIGH7.5Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. ...
CVE-2026-41006HIGH7.5Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media ty...
CVE-2026-40984HIGH7.5In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (...
CVE-2026-40983HIGH7.5In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (...
CVE-2026-26236HIGH7.5A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul...
CVE-2026-11623MEDIUM4.5A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now