8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.springframework:spring-expression is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.3
CVE-2026-41851
Spring Framework Denial of Service via Unbounded Cache in SpEL
HIGH 7.5
CVE-2026-41850
Spring Framework Algorithmic Denial of Service via SpEL Expressions
LOW 3.7
CVE-2026-41852
Spring Framework Arbitrary Method Invocation in SpEL Expressions
MEDIUM 4.3
CVE-2024-38808
Spring Framework vulnerable to Denial of Service
HIGH 7.5
CVE-2026-41849
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
MEDIUM 6.5
CVE-2023-20861
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
HIGH 7.5
CVE-2023-20863
Spring Framework vulnerable to denial of service
MEDIUM 6.5
CVE-2022-22950
Allocation of Resources Without Limits or Throttling in Spring Framework
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes