Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Spring
Spring Web Services
Information Exposure
>=2.4.0 <=2.4.7, >=3.1.0 <=3.1.8, >=4.0.0 <=4.0.18, >=4.1.0 <=4.1.3, >=5.0.0 <=5.0.1
Jun 11, 2026
Medium
Spring
Spring Web Services
Information Exposure
>=2.4.0 <=2.4.7, >=3.1.0 <=3.1.8, >=4.0.0 <=4.0.18, >=4.1.0 <=4.1.3, >=5.0.0 <=5.0.1
Jun 11, 2026
Medium
Spring
Spring Web Services
Authorization Bypass
>=2.4.0 <=2.4.7, >=3.1.0 <=3.1.8, >=4.0.0 <=4.0.18, >=4.1.0 <=4.1.3, >=5.0.0 <=5.0.1
Jun 11, 2026
High
Spring
Spring Web Services
Signature Forgery
>=2.4.0 <=2.4.7, >=3.1.0 <=3.1.8, >=4.0.0 <=4.0.18, >=4.1.0 <=4.1.3, >=5.0.0 <=5.0.1
Jun 11, 2026
Medium
Spring
Spring Web Flow
Cross-Site Scripting
>=2.5.0 <=2.5.1, >=3.0.0 <=3.0.1, 4.0.0
Jun 11, 2026
Medium
Spring
Spring Web Flow
Remote Code Execution
>=2.5.0 <=2.5.1, >=3.0.0 <=3.0.1, 4.0.0
Jun 11, 2026
Low
Django
Django
Security Misconfiguration
<=3.2.25, <=4.2.28, <=5.2.12, <=6.0.2
Jun 2, 2026
No results found
Please enter a valid Vulnerability ID number or Technology name.
