Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Low
Spring
Spring Cloud Stream
Incorrectly Configured Access Control
>=3.0.0.RELEASE <=3.0.13.RELEASE, >=3.1.0 <=3.1.6, >=3.2.0 <=3.2.10, >=4.0.0 <=4.0.5, >=4.1.0 <=4.1.6, >=4.2.0 <=4.2.3, >=4.3.0 <=4.3.3, >=5.0.0 <5.0.3
Aug 25, 2026
Medium
Spring
Spring AMQP
Information Exposure
>= 3.0.0 < 3.2.13, >= 4.0.0 < 4.0.5, >= 4.1.0 < 4.1.1
Aug 25, 2026
Low
Spring
Spring Cloud Function
Server-Side Request Forgery
>=4.0.4 <=4.1.6, >=4.2.0 <=4.2.7, >=4.3.0 <=4.3.4, >=5.0.0 <5.0.4
Aug 25, 2026
Medium
Spring
Spring for Apache Kafka
Denial of Service
>=2.7.0 <=2.8.12, >=2.9.0 <=2.9.14, >=3.0.0 <=3.3.16, >=4.0.0 <=4.0.6, 4.1.0
Aug 25, 2026
Medium
Spring
Spring for Apache Kafka
Server-Side Request Forgery
>=2.3.0 <2.8.13, >=2.9.0 <2.9.15, >=3.0.0 <3.3.17, >=4.0.0 <4.0.7, >=4.1.0 <4.1.1
Aug 25, 2026
High
Spring
Spring for GraphQL
Denial of Service
>=1.2.0 <=1.3.9, >=1.4.0 <=1.4.6, >=2.0.0 <=2.0.4
Aug 21, 2026
Critical
Spring
Spring Security
Security Misconfiguration
>=7.1.0 <7.1.1, >=7.0.0 <7.0.7, >=6.5.0 <=6.5.11, >=6.4.0 <=6.4.18, >=6.0.0 <=6.3.10, >=5.8.0 <=5.8.27, >=5.7.0 <=5.7.25, >=5.0.0 <=5.6.12, >=4.2.9.RELEASE <=4.2.20.RELEASE
Aug 21, 2026
High
Spring
Spring Security
Authorization Bypass
>= 6.5.0 <= 6.5.11, >= 7.0.0 <= 7.0.6, 7.1.0
Aug 21, 2026
High
Spring
Spring Integration
Information Exposure
>=7.1.0 <7.1.1, >=7.0.0 <7.0.6, >=5.1.0 <=6.5.10
Aug 21, 2026
Medium
Spring
Spring AMQP
Denial of Service
>=4.1.0 <4.1.1, >=4.0.0 <4.0.5, >=3.0.0 <=3.2.12, >=2.1.0 <=2.4.18
Aug 20, 2026
Medium
Spring
Spring Integration
Information Exposure
>=7.1.0 <7.1.1, >=7.0.0 <7.0.6, >=6.5.0 <=6.5.10, >=6.0.0 <=6.4.12
Aug 20, 2026
High
Apache Struts
Apache Struts
Denial of Service
>=2.1.8 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <=6.10.0, >=7.0.0 <=7.2.1
Aug 19, 2026
High
.NET
.NET SDK
Resource Injection
Microsoft.Build.Tasks.Core >= 17.0.0 <= 17.8.3; as bundled in the .NET 6 SDK through NES for .NET 6.0.44
Aug 19, 2026
High
.NET
.NET SDK
Improper Link Resolution Before File Access ('Link Following')
Microsoft.Build.Tasks.Core >= 17.8.0 <= 17.14.8; as bundled in the .NET 6 SDK through NES for .NET 6.0.44
Aug 19, 2026
No results found
Please enter a valid Vulnerability ID number or Technology name.
