|
821
|
4.0 |
MEDIUM
Network
|
-
|
-
|
Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-41714
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
822
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters.
Affected versions:
Spring Data Commons …
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-41711
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
823
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after…
New
|
CWE-601
Open Redirect
|
CVE-2026-41706
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
824
|
4.4 |
MEDIUM
Network
|
-
|
-
|
Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter.
Affected versions:
Spring AMQP 4.0.0 through 4.0.3; 3.2.…
New
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2026-41701
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
825
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An attacker can sup…
New
|
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-41697
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
826
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to …
New
|
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-41696
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
827
|
7.5 |
HIGH
Network
|
-
|
-
|
Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolutio…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-41695
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
828
|
3.7 |
LOW
Network
|
-
|
-
|
Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloa…
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-41694
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
829
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an inva…
New
|
CWE-601
Open Redirect
|
CVE-2026-41008
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
830
|
7.6 |
HIGH
Network
|
-
|
-
|
An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters.
Affected versions:
Spring Security 5.7.0 throug…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-41003
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|