18 Total advisories
18 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.springframework:spring-webflux is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.9
CVE-2026-41841
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
MEDIUM 5.3
CVE-2026-41853
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
MEDIUM 5.9
CVE-2026-41840
Spring Framework Denial of Service via Multipart Requests in WebFlux
LOW 3.1
CVE-2026-22741
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
LOW 2.6
CVE-2026-22735
Spring MVC and WebFlux has Server Sent Event stream corruption
HIGH 7.5
CVE-2026-41842
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
MEDIUM 4.2
CVE-2026-41844
Spring Framework Open Redirect in Spring MVC and WebFlux
MEDIUM 5.9
CVE-2026-41843
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
MEDIUM 4.2
CVE-2026-41839
Spring Framework Escalation via Session Fixation in WebFlux
MEDIUM 5.3
CVE-2026-22745
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
MEDIUM 6.5
CVE-2026-22740
Spring Framework DoS with Multipart Temp Files in WebFlux
MEDIUM 5.9
CVE-2026-22737
Spring Framework Improper Path Limitation with Script View Templates
HIGH 7.5
CVE-2024-38816
Path traversal vulnerability in functional web frameworks
HIGH 7.5
CVE-2020-5398
RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application
MEDIUM 4.8
CVE-2026-41847
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
CRITICAL 9.8
CVE-2022-22965
Remote Code Execution in Spring Framework
HIGH 7.5
CVE-2024-38819
Spring Framework Path Traversal vulnerability
MEDIUM 5.3
CVE-2020-5397
CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes