Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.

Codey gradient
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Spring
Spring Framework
Authorization Bypass
>=5.2.5 <=5.2.25, >=5.3.0 <=5.3.49, >=6.0.0 <=6.0.30, >=6.1.0 <=6.1.28, >=6.2.0 <=6.2.19, >=7.0.0 <=7.0.8
Aug 29, 2026
Medium
Spring
Spring Framework
Denial of Service
<=5.2.25, >=5.3.0 <=5.3.49, >=6.0.0 <=6.0.30, >=6.1.0 <=6.1.28, >=6.2.0 <=6.2.19, >=7.0.0 <=7.0.8
Aug 29, 2026
Low
Spring
Spring Framework
Content Spoofing
>=6.2.0 <=6.2.19, >=7.0.0 <=7.0.8
Aug 29, 2026
Medium
Spring
Spring Framework
Information Exposure
>=6.2.0 <=6.2.19, >=7.0.0 <=7.0.8
Aug 29, 2026
Medium
Spring
Spring Framework
Denial of Service
>=5.2.0 <=5.2.25, >=5.3.0 <=5.3.49, >=6.0.0 <=6.0.30, >=6.1.0 <=6.1.28, >=6.2.0 <=6.2.19, >=7.0.0 <=7.0.8
Aug 29, 2026
Medium
Spring
Spring Integration
Remote Code Execution
>= 3.0.0 <= 5.5.21, >= 6.0.0 <= 6.4.12, >= 6.5.0 <= 6.5.10, >= 7.0.0 < 7.0.6, >= 7.1.0 < 7.1.1
Aug 29, 2026
Medium
Spring
Spring Framework
URL Redirect/Open Redirect
<=5.2.25, >=5.3.0 <=5.3.49, >=6.0.0 <=6.0.30, >=6.1.0 <=6.1.28, >=6.2.0 <=6.2.19, >=7.0.0 <=7.0.8
Aug 28, 2026
Medium
Spring
Spring Framework
Uncontrolled Resource Consumption
<=5.2.25, >=5.3.0 <=5.3.49, >=6.0.0 <=6.0.30, >=6.1.0 <=6.1.28, >=6.2.0 <=6.2.19, >=7.0.0 <=7.0.8
Aug 28, 2026
Critical
Spring
Spring Framework
Server-Side Request Forgery
<=5.2.25.RELEASE, >=5.3.0 <=5.3.49, >=6.0.0 <=6.0.30, >=6.1.0 <=6.1.28, >=6.2.0 <=6.2.19, >=7.0.0 <=7.0.8
Aug 28, 2026
Medium
Spring
Spring Security
Information Exposure
7.1.0, >=7.0.0 <=7.0.6, >=6.5.0 <=6.5.11, >=6.4.0 <=6.4.18, >=6.3.0 <=6.3.10, >=6.2.0 <=6.2.8, >=5.8.0 <=5.8.27, >=5.7.0 <=5.7.25, 5.5.8, 4.2.20.RELEASE
Aug 27, 2026
Medium
Spring
Spring Framework
Denial of Service
>=6.1.0 <=6.1.28, >=6.2.0 <=6.2.19, >=7.0.0 <=7.0.8
Aug 27, 2026
Medium
Spring
Spring Framework
URL Redirect/Open Redirect
>=6.2.0 <=6.2.19, >=7.0.0 <=7.0.8
Aug 27, 2026
High
Spring
Spring Security
Authorization Bypass
7.1.0, >=7.0.0 <7.0.7, >=6.5.0 <=6.5.11, >=6.4.0 <=6.4.18
Aug 27, 2026
Low
Node.js
Node.js
Concurrent Execution using Shared Resource with Improper Synchronization
Node.js 22.x through v22.22.3; v24.x through v24.16.0; v26.x through v26.3.0
Aug 26, 2026
Low
Node.js
Node.js
Incorrect Authorization
22.x ≤ 22.23.1; 24.x ≤ 24.18.0; 26.x ≤ 26.5.0; 20.x (EOL, all versions)
Aug 26, 2026
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.

Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.