CVE-2018-1257 is a regular expression denial-of-service (ReDoS) vulnerability affecting Spring Framework versions 5.0.x prior to 5.0.6, 4.3.x prior to 4.3.17, and older unsupported versions. It specifically impacts applications exposing STOMP over WebSocket endpoints with a simple, in-memory STOMP broker via the spring-messaging module, with affected products including Oracle, Red Hat, and VMware. The vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity and no user interaction, leading to a high impact on availability (denial of service). While the EPSS score is low, suggesting a low probability of exploitation, the FAUCET Risk Score is 39/100. There is no evidence of active exploitation, nor is exploit code available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting it is not a high-profile threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3.17CPE matchmatch criteria | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.0.6CPE matchmatch criteria | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:openshift:-:*:*:*:*:*:*:* | ||
9.3.3CPE matchmatch criteria | cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.3:*:*:*:*:*:*:* | ||
9.3.4CPE matchmatch criteria | cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.