maven

org.springframework:spring-webmvc

View on maven registry
25 Total advisories
25 Vulnerabilities
0 Malware

Dependency scanning

Check whether org.springframework:spring-webmvc is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 5.9
Maven

CVE-2026-41841

Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

MEDIUM 5.3
Maven

CVE-2026-41853

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

LOW 3.1
Maven

CVE-2026-22741

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

LOW 2.6
Maven

CVE-2026-22735

Spring MVC and WebFlux has Server Sent Event stream corruption

HIGH 7.1
Maven

CVE-2026-41845

Spring Framework Cross-site Scripting via JavaScriptUtils

HIGH 7.5
Maven

CVE-2026-41842

Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

MEDIUM 4.2
Maven

CVE-2026-41844

Spring Framework Open Redirect in Spring MVC and WebFlux

MEDIUM 5.9
Maven

CVE-2026-41846

Spring Framework Cross-site Scripting via JSP Form Tags

MEDIUM 5.9
Maven

CVE-2026-41843

Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux

MEDIUM 5.3
Maven

CVE-2026-22745

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources

MEDIUM 5.9
Maven

CVE-2026-22737

Spring Framework Improper Path Limitation with Script View Templates

MEDIUM 5.9
Maven

CVE-2025-41242

Spring Framework MVC Applications Path Traversal Vulnerability

HIGH 7.5
Maven

CVE-2024-38816

Path traversal vulnerability in functional web frameworks

HIGH 7.5
Maven

CVE-2020-5398

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

CRITICAL 9.8
Maven KEV

CVE-2022-22965

Remote Code Execution in Spring Framework

CRITICAL 9.1
Maven

CVE-2023-20860

Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch

HIGH 7.5
Maven

CVE-2024-38819

Spring Framework Path Traversal vulnerability

MEDIUM 5.3
Maven

CVE-2024-38828

Spring MVC controller vulnerable to a DoS attack

HIGH 7.5
Maven

CVE-2023-34053

Spring Framework vulnerable to denial of service

UNKNOWN
Maven

CVE-2014-0054

Cross-Site Request Forgery in Spring Framework

UNKNOWN
Maven

CVE-2014-3625

Improper Limitation of a Pathname to a Restricted Directory in Spring Framework

UNKNOWN
Maven

CVE-2014-1904

Improper Neutralization of Input During Web Page Generation in Spring Framework

MEDIUM 5.3
Maven

CVE-2020-5397

CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux

HIGH 7.5
Maven

CVE-2016-9878

Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized

HIGH 8.8
Maven

CVE-2014-0225

Improper Restriction of XML External Entity Reference in Spring Framework

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes