19 Total advisories
19 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.springframework:spring-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
LOW 3.7
CVE-2026-41848
Spring Framework Denial of Service via AntPathMatcher
HIGH 7.5
CVE-2025-41249
Spring Framework annotation detection mechanism may result in improper authorization
HIGH 7.5
CVE-2024-22233
Spring Framework server Web DoS Vulnerability
UNKNOWN
CVE-2009-1190
Spring Framework Inefficient Regular Expression Complexity
UNKNOWN
CVE-2014-3578
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
UNKNOWN
CVE-2011-2730
Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework
HIGH 7.5
CVE-2018-1272
Possible privilege escalation in org.springframework:spring-core
MEDIUM 4.3
CVE-2021-22060
Log entry injection in Spring Framework
MEDIUM 6.5
CVE-2018-1257
Denial of Service in org.springframework:spring-core
UNKNOWN
CVE-2011-2894
Spring Framework and Spring Security vulnerable to Deserialization of Untrusted Data
HIGH 7.5
CVE-2016-5007
Spring Security and Spring Framework may not recognize certain paths that should be protected
UNKNOWN
CVE-2015-0201
Moderate severity vulnerability that affects org.springframework:spring-core
HIGH 7.5
CVE-2018-15756
Denial of Service in Spring Framework
MEDIUM 4.3
CVE-2021-22096
Improper Output Neutralization for Logs in Spring Framework
MEDIUM 5.9
CVE-2018-11040
Moderate severity vulnerability that affects org.springframework:spring-core
MEDIUM 5.9
CVE-2018-1271
Path Traversal in org.springframework:spring-core
MEDIUM 5.3
CVE-2018-1199
Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core
HIGH 8.8
CVE-2018-1258
Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass
HIGH 8.6
CVE-2015-5211
Files or Directories Accessible to External Parties in org.springframework:spring-core
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes