Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Jackson
jackson-databind
Resource Injection
>=2.8.0 <2.18.10, >=2.19.0 <2.21.6, >=2.22.0 <2.22.2, >=3.0.0 <3.1.6, >=3.2.0 <3.2.2
Sep 4, 2026
Medium
Spring
Spring Integration
Path Traversal
>=7.1.0 <7.1.1, >=7.0.0 <7.0.6, >=6.1.0 <=6.5.10
Sep 3, 2026
Medium
Spring
Spring AI
Authorization Bypass
>=1.0.0 <=1.0.9, >=1.1.0 <=1.1.8, 2.0.0
Sep 3, 2026
Medium
Spring
Spring for GraphQL
Denial of Service
>=1.3.0 <=1.3.9, >=1.4.0 <=1.4.6, >=2.0.0 <=2.0.4
Sep 2, 2026
Medium
Spring
Spring Batch
Denial of Service
>=6.0.0 <=6.0.4, >=5.2.0 <=5.2.6, >=5.1.0 <=5.1.3, >=4.3.0 <=4.3.13
Sep 2, 2026
High
Spring
Spring Cloud Gateway
Server-Side Request Forgery
>=3.1.4 <=3.1.13, >=4.0.0 <=4.2.9, >=4.3.0 <=4.3.5, >=5.0.0 <=5.0.2
Sep 2, 2026
Low
Spring
Spring Cloud Function
Information Exposure
>=3.1.0 <=4.1.6, >=4.2.0 <=4.2.7, >=4.3.0 <=4.3.4, >=5.0.0 <5.0.4
Sep 2, 2026
Low
Spring
Spring Cloud Function
Information Exposure
>=4.0.3 <=4.1.6, >=4.2.0 <=4.2.7, >=4.3.0 <=4.3.4, >=5.0.0 <5.0.4
Sep 2, 2026
Low
Spring
Spring Cloud Function
Information Exposure
>=3.1.1 <=4.1.6, >=4.2.0 <=4.2.7, >=4.3.0 <=4.3.4, >=5.0.0 <5.0.4
Sep 2, 2026
Low
Spring
Spring Cloud Function
Incorrectly Configured Access Control
>=2.0.0 <=3.2.16, >=4.0.0 <=4.1.6, >=4.2.0 <=4.2.7, >=4.3.0 <=4.3.4, >=5.0.0 <5.0.4
Sep 2, 2026
Low
Spring
Spring Cloud Function
Incorrectly Configured Access Control
>=4.0.3 <=4.1.6, >=4.2.0 <=4.2.7, >=4.3.0 <=4.3.4, >=5.0.0 <5.0.4
Sep 2, 2026
High
Spring
Spring Cloud Config
Authorization Bypass
>=5.0.0 <=5.0.4, >=4.3.0 <=4.3.4, >=4.0.0 <=4.2.8, <=3.1.14
Sep 1, 2026
High
Spring
Spring Cloud Config
Path Traversal
>=5.0.0 <=5.0.4, >=4.3.0 <=4.3.4, >=4.0.0 <=4.2.8, <=3.1.14
Sep 1, 2026
Medium
Spring
Spring Cloud Config
Information Exposure
>=5.0.0 <=5.0.4, >=4.3.0 <=4.3.4, >=4.0.0 <=4.2.8, <=3.1.14
Sep 1, 2026
Low
Spring
Spring Cloud Stream
Information Exposure
>=4.0.0 <=4.0.5, >=4.1.0 <=4.1.6, >=4.2.0 <=4.2.3, >=4.3.0 <=4.3.3, >=5.0.0 <5.0.3
Sep 1, 2026
No results found
Please enter a valid Vulnerability ID number or Technology name.
