Spring Boot

Vendor:

First CVE: Jan 4, 2018 · Active for 8 years

19
Total CVEs
More Total CVEs than 93% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Spring Boot over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 4, 2018
8 years ago
Most Recent CVE
Apr 28, 2026
88 days ago

CVE Severity & Scoring

Spring Boot19 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local3 (15.8%)
Network14 (73.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (10.5%)
Attack Complexity
Low13 (68.4%)
High6 (31.6%)
Unknown0 (0.0%)
User Interaction
None19 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (15.8%)
High1 (5.3%)
None15 (78.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.
Jan 4, 20189.888NOYES
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servle
Apr 28, 20269.141NONO
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6),
Apr 28, 20269.841NONO
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boo
Apr 27, 20269.139NONO
Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they ar
Apr 28, 20267.535NONO
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `tru
Apr 28, 20267.035NONO
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this coul
Apr 28, 20267.535NONO
When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the ap
Apr 28, 20266.733NONO
In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. U
Apr 20, 20239.831NONO
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a s
Mar 19, 20268.130NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.3% of CVEs· 97th percentile
ExploitDB
1 CVE
5.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Spring Boot

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.6.017.51.6%00
2.0.027.531.7%01