Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
High
Spring
Spring for GraphQL
Information Exposure
>=1.0.0 <=1.0.7, >=1.1.0 <=1.3.9, >=1.4.0 <=1.4.6, >=2.0.0 <=2.0.5
Aug 31, 2026
Medium
Spring
Spring AMQP
Incorrectly Configured Access Control
>= 2.1.7 <= 2.4.18, >= 3.0.0 <= 3.2.12, >= 4.0.0 <= 4.0.4, 4.1.0
Aug 31, 2026
High
Spring
Spring AI
Incorrectly Configured Access Control
>=1.0.0 <=1.0.9, >=1.1.0 <=1.1.8, 2.0.0
Aug 31, 2026
High
Spring
Spring AI
Denial of Service
>=1.0.0 <=1.0.9, >=1.1.0 <=1.1.8, 2.0.0
Aug 31, 2026
High
Spring
Spring for GraphQL
Insufficient Verification of Data Authenticity
>=1.0.0 <=1.0.7, >=1.1.0 <=1.3.9, >=1.4.0 <=1.4.6, >=2.0.0 <=2.0.4
Aug 31, 2026
High
Spring
Spring Authorization Server
Cross-Site Scripting
>=1.5.0 <=1.5.8, >=1.4.0 <=1.4.11, >=0.0.2 <=1.3.7
Aug 31, 2026
High
Spring
Spring Data REST
Authorization Bypass
>=5.1.0 <5.1.1, >=5.0.0 <5.0.7, >=4.5.0 <=4.5.13, >=4.0.0 <=4.4.15, <=3.7.20
Aug 30, 2026
Medium
Spring
Spring Integration
Denial of Service
>= 6.1.0 <= 6.4.12, >= 6.5.0 <= 6.5.10, >= 7.0.0 < 7.0.6, >= 7.1.0 < 7.1.1
Aug 29, 2026
Medium
Spring
Spring Integration
Remote Code Execution
>=1.0.2 <=5.5.21, >=6.0.0 <=6.4.12, >=6.5.0 <=6.5.10, >=7.0.0 <7.0.6, >=7.1.0 <7.1.1
Aug 29, 2026
Medium
Spring
Spring Integration
Path Traversal
>= 6.1.0 <= 6.4.12, >= 6.5.0 <= 6.5.10, >= 7.0.0 < 7.0.6, >= 7.1.0 < 7.1.1
Aug 29, 2026
Medium
Spring
Spring Integration
Server-Side Request Forgery
>= 2.0.0 <= 5.5.21, >= 6.0.0 <= 6.4.12, >= 6.5.0 <= 6.5.10, >= 7.0.0 < 7.0.6, >= 7.1.0 < 7.1.1
Aug 29, 2026
Medium
Spring
Spring Integration
Denial of Service
>= 4.1.1 < 5.5.22, >= 6.0.0 < 6.4.13, >= 6.5.0 < 6.5.11, >= 7.0.0 < 7.0.6, >= 7.1.0 < 7.1.1
Aug 29, 2026
Medium
Spring
Spring Integration
Resource Injection
>=5.0.0 <=5.4.13, >=5.5.0 <=5.5.20, >=6.0.0 <=6.1.9, >=6.2.0 <=6.2.11, >=6.3.0 <=6.3.11, >=6.4.0 <=6.4.10, >=6.5.0 <=6.5.10, >=7.0.0 <=7.0.5, >=7.1.0 <=7.1.0
Aug 29, 2026
Medium
Spring
Spring Integration
Information Exposure
>=7.1.0 <7.1.1, >=7.0.0 <7.0.6, >=2.2.1 <=6.5.10
Aug 29, 2026
High
Spring
Spring Integration
Remote Code Execution
>=7.1.0 <7.1.1, >=7.0.0 <7.0.6, >=6.5.0 <=6.5.10, >=6.4.0 <=6.4.12
Aug 29, 2026
No results found
Please enter a valid Vulnerability ID number or Technology name.
