VYPR

Spring Tools for VSCode

by Spring Projects

CVEs (2)

  • CVE-2026-59326Jul 30, 2026
    risk 0.00cvss epss 0.00

    The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently…

  • CVE-2026-47858Jul 30, 2026
    risk 0.00cvss epss 0.00

    Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for…