VENDOR

Spring vulnerabilities: CVEs, exploitation and patches

Every Spring CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-47890
    Spring Framework SSE stream corruption Spring Spring Framework ·
    CRITICAL 9.8
  2. CVE-2026-47891
    Spring Framework Aalto XML maxInMemorySize bypass Spring Spring Framework ·
    CRITICAL 9.8
  3. CVE-2026-59313
    Spring Framework stream corruption in SSE Spring Spring Framework ·
    CRITICAL 9.8
3 CVEs · page 1 of 1