13 Total advisories
13 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.springframework:spring-web is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.3
CVE-2024-38809
Spring Framework DoS via conditional HTTP request
MEDIUM 6.5
CVE-2025-41234
Spring Framework vulnerable to a reflected file download (RFD)
MEDIUM 5.3
CVE-2024-38820
Spring Framework DataBinder Case Sensitive Match Exception
HIGH 8.1
CVE-2024-22262
Spring Framework URL Parsing with Host Validation
HIGH 8.1
CVE-2024-22259
Spring Framework URL Parsing with Host Validation Vulnerability
HIGH 8.1
CVE-2024-22243
Spring Web vulnerable to Open Redirect or Server Side Request Forgery
CRITICAL 9.8
CVE-2016-1000027
Pivotal Spring Framework contains unsafe Java deserialization methods
MEDIUM 4.2
CVE-2026-41854
Spring Framework Server-Side Request Forgery via UriComponentsBuilder
MEDIUM 5.4
CVE-2013-6430
Improper Neutralization of Input During Web Page Generation in Spring Framework
UNKNOWN
CVE-2013-6429
Cross-Site Request Forgery in Spring Framework
MEDIUM 5.9
CVE-2018-11039
Spring Framework Cross Site Tracing (XST)
MEDIUM 5.5
CVE-2015-3192
Pivotal Spring Framework DoS Attack with XML Input
HIGH 7.8
CVE-2021-22118
Improper Privilege Management in Spring Framework
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes