Dependency scanning
Check whether org.springframework:spring-webmvc is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-41841
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
CVE-2026-41853
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
CVE-2026-22741
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
CVE-2026-22735
Spring MVC and WebFlux has Server Sent Event stream corruption
CVE-2026-41845
Spring Framework Cross-site Scripting via JavaScriptUtils
CVE-2026-41842
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
CVE-2026-41844
Spring Framework Open Redirect in Spring MVC and WebFlux
CVE-2026-41846
Spring Framework Cross-site Scripting via JSP Form Tags
CVE-2026-41843
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
CVE-2026-22745
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
CVE-2026-22737
Spring Framework Improper Path Limitation with Script View Templates
CVE-2025-41242
Spring Framework MVC Applications Path Traversal Vulnerability
CVE-2024-38816
Path traversal vulnerability in functional web frameworks
CVE-2020-5398
RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application
CVE-2022-22965
Remote Code Execution in Spring Framework
CVE-2023-20860
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
CVE-2024-38819
Spring Framework Path Traversal vulnerability
CVE-2024-38828
Spring MVC controller vulnerable to a DoS attack
CVE-2023-34053
Spring Framework vulnerable to denial of service
CVE-2014-0054
Cross-Site Request Forgery in Spring Framework
CVE-2014-3625
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
CVE-2014-1904
Improper Neutralization of Input During Web Page Generation in Spring Framework
CVE-2020-5397
CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux
CVE-2016-9878
Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
CVE-2014-0225
Improper Restriction of XML External Entity Reference in Spring Framework
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes