org.springframework.boot:spring-boot
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework.boot:spring-bootpage 1 of 1
- CVE-2018-1196MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.5.102018-03-19
vulnerable: 1.5.0.RELEASE ... 1.5.9.RELEASE (10 versions)
Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a sy…
- CVE-2022-27772HIGHCVSS 7.8EG 7.8✓ Fixed in 2.2.11.RELEASE2022-03-30
vulnerable: 1.0.0.RELEASE ... 2.2.9.RELEASE (105 versions)
spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: Thi…
- CVE-2025-22235HIGHCVSS 7.3EG 7.3✓ Fixed in 3.4.52025-04-28
vulnerable: 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.4.4
EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. Your application may be affected by this if all the following conditions are met: …
- CVE-2026-40973HIGHCVSS 7.0EG 7.02026-04-28
vulnerable: 1.0.0.RELEASE ... 2.7.9 (186 versions)
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, thi…
- CVE-2026-40976CRITICALCVSS 9.1EG 9.1✓ Fixed in 4.0.62026-04-28
vulnerable: 4.0.0 ... 4.0.5 (6 versions)
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configurat…
Check whether org.springframework.boot:spring-boot is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework.boot:spring-boot CVEs against the assets you own.
Start Free Scan →