VYPR

Maven package

org.springframework/spring-webflux

pkg:maven/org.springframework/spring-webflux

Vulnerabilities (10)

  • CVE-2026-22745MedApr 29, 2026
    affected >= 7.0.0, < 7.0.7fixed 7.0.7

    Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is

  • CVE-2026-22741LowApr 29, 2026
    affected >= 7.0.0, < 7.0.7fixed 7.0.7

    Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuri

  • CVE-2026-22740MedApr 29, 2026
    affected >= 7.0.0, < 7.0.7fixed 7.0.7

    A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsuppo

  • CVE-2026-22737MedMar 20, 2026
    affected >= 7.0.0-M1, < 7.0.6fixed 7.0.6

    Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 throug

  • CVE-2026-22735LowMar 20, 2026
    affected >= 7.0.0-M1, < 7.0.6fixed 7.0.6

    Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

  • CVE-2024-38819HigDec 19, 2024
    affected >= 6.1.0, < 6.1.14fixed 6.1.14

    Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the S

  • CVE-2024-38816HigSep 13, 2024
    affected >= 6.1.0, < 6.1.13fixed 6.1.13

    Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the S

  • CVE-2022-22965KEVApr 1, 2022
    affected < 5.2.20.RELEASEfixed 5.2.20.RELEASE

    A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e.

  • CVE-2020-5397Jan 17, 2020
    affected >= 5.2.0, < 5.2.3fixed 5.2.3

    Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requ

  • CVE-2020-5398Jan 16, 2020
    affected >= 5.2.0.RELEASE, < 5.2.3.RELEASEfixed 5.2.3.RELEASE

    In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute