Spring Boot
Vendor:
First CVE: Jan 4, 2018 · Active for 8 years
19
Total CVEs
More Total CVEs than 93% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spring Boot over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 4, 2018
8 years ago
Most Recent CVE
Apr 28, 2026
88 days ago
CVE Severity & Scoring
Spring Boot19 CVEs
21%
42%
37%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (15.8%)
Network14 (73.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (10.5%)
Attack Complexity
Low13 (68.4%)
High6 (31.6%)
Unknown0 (0.0%)
User Interaction
None19 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (15.8%)
High1 (5.3%)
None15 (78.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8046CRITICAL Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5. | Jan 4, 2018 | 9.8 | 88 | NO | YES |
CVE-2026-40976CRITICAL In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servle | Apr 28, 2026 | 9.1 | 41 | NO | NO |
CVE-2026-40974CRITICAL Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), | Apr 28, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-40971CRITICAL When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker.
Affected: Spring Boo | Apr 27, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-40975HIGH Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they ar | Apr 28, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-40973HIGH A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `tru | Apr 28, 2026 | 7.0 | 35 | NO | NO |
CVE-2026-40972HIGH An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this coul | Apr 28, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-40977MEDIUM When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the ap | Apr 28, 2026 | 6.7 | 33 | NO | NO |
CVE-2023-20873CRITICAL In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. U | Apr 20, 2023 | 9.8 | 31 | NO | NO |
CVE-2026-22731HIGH Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a s | Mar 19, 2026 | 8.1 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.3% of CVEs· 97th percentile
ExploitDB
1 CVE
5.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Spring Boot
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.6.0 | 1 | 7.5 | 1.6% | 0 | 0 |
| 2.0.0 | 2 | 7.5 | 31.7% | 0 | 1 |