Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Low
Node.js
Node.js
HTTP Request Smuggling
<=26.5.0; <=24.18.0; <=22.23.1; all End-of-Life release lines, including 12.x, 14.x, 16.x, 18.x, and 20.x
Aug 26, 2026
Medium
Node.js
Node.js
Denial of Service
<=22.23.1; >=24.0.0 <=24.18.0; >=26.0.0 <=26.5.0; all End-of-Life release lines, including 12.x, 14.x, 16.x, 18.x, and 20.x
Aug 26, 2026
Medium
Spring
Spring Data REST
Authorization Bypass
>=5.1.0 <=5.1.0, >=5.0.0 <=5.0.6, >=4.5.0 <=4.5.13, >=4.0.0 <=4.4.15, >=3.1.0 <=3.7.20
Aug 26, 2026
Medium
Spring
Spring Data JPA
Information Exposure
<=2.7.18, >=3.0.0 <=3.4.15, >=3.5.0 <=3.5.13, >=4.0.0 <=4.0.6, 4.1.0
Aug 26, 2026
Medium
Spring
Spring Integration
Resource Injection
<= 5.5.21, >= 6.0.0 <= 6.4.12, >= 6.5.0 <= 6.5.10, >= 7.0.0 < 7.0.6, >= 7.1.0 < 7.1.1
Aug 26, 2026
Medium
Spring
Spring AMQP
Denial of Service
>=1.4.2 <=2.4.18, >=3.0.0 <=3.2.12, >=4.0.0 <4.0.5, >=4.1.0 <4.1.1
Aug 26, 2026
High
Node.js
Node.js
Denial of Service
<=24.18.0; <=22.23.1; all End-of-Life release lines, including 12.x, 14.x, 16.x, 18.x, and 20.x
Aug 26, 2026
Medium
Node.js
Node.js
Denial of Service
<=26.5.0; <=24.18.0; <=22.23.1; all End-of-Life release lines, including 12.x, 14.x, 16.x, 18.x, and 20.x
Aug 26, 2026
Low
Node.js
Node.js
Authorization Bypass
22.x ≤ 22.23.1; 24.x ≤ 24.18.0; 26.x ≤ 26.5.0; 20.x (EOL, all)
Aug 26, 2026
Medium
Node.js
Node.js
Weak Authentication
<=26.5.0; <=24.18.0; <=22.23.1; all End-of-Life release lines, including 12.x, 14.x, 16.x, 18.x, and 20.x
Aug 26, 2026
Medium
Spring
Spring Batch
Remote Code Execution
>=5.0.0 <=5.2.6, >=6.0.0 <=6.0.4
Aug 26, 2026
Medium
Spring
Spring Batch
Remote Code Execution
>= 6.0.0 <= 6.0.4, >= 5.0.0 <= 5.2.6
Aug 26, 2026
Medium
Spring
Spring Cloud Config
Denial of Service
>=5.0.0 <=5.0.4, >=4.3.0 <=4.3.4, >=4.0.0 <=4.2.8, <=3.1.14
Aug 26, 2026
Low
Spring
Spring Cloud Stream
Denial of Service
>=4.0.4 <=4.0.5, >=4.1.0 <=4.1.6, >=4.2.0 <=4.2.3, >=4.3.0 <=4.3.3, >=5.0.0 <5.0.3
Aug 25, 2026
Low
Spring
Spring Cloud Stream
Denial of Service
>=4.2.0 <=4.2.6, >=4.3.0 <=4.3.3, >=5.0.0 <=5.0.2
Aug 25, 2026
No results found
Please enter a valid Vulnerability ID number or Technology name.
