检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-WXPP-56Q6-5PCG CVE-2026-41851 | Spring Framework Denial of Service via Unbounded Cache in SpEL | 中危 | Mavenorg.springframework:spring-expression | 已审查 | 2026-06-09 14:31 | 2026-07-31 00:38 |
| GHSA-VQGP-PF68-6947 CVE-2026-41847 | Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Mavenorg.springframework:spring-webflux |
| 已审查 |
| 2026-06-09 14:31 |
| 2026-07-31 02:30 |
| GHSA-R5W3-XV2F-J59Q CVE-2026-41850 | Spring Framework Algorithmic Denial of Service via SpEL Expressions | 高危 | Mavenorg.springframework:spring-expression | 已审查 | 2026-06-09 14:31 | 2026-07-31 02:26 |
| GHSA-CJPG-RGQ5-FR37 CVE-2026-41853 | Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux | 中危 | Mavenorg.springframework:spring-webflux+1 | 已审查 | 2026-06-09 14:31 | 2026-07-31 02:33 |
| GHSA-9F52-RJQV-25QV CVE-2026-41852 | Spring Framework Arbitrary Method Invocation in SpEL Expressions | 低危 | Mavenorg.springframework:spring-expression | 已审查 | 2026-06-09 14:31 | 2026-07-31 02:13 |
| GHSA-957G-F97V-VPPC CVE-2026-41846 | Spring Framework Cross-site Scripting via JSP Form Tags | 中危 | Mavenorg.springframework:spring-webmvc | 已审查 | 2026-06-09 14:31 | 2026-07-31 02:37 |
| GHSA-7M2P-62GW-P8QQ CVE-2026-41854 | Spring Framework Server-Side Request Forgery via UriComponentsBuilder | 中危 | Mavenorg.springframework:spring-web | 已审查 | 2026-06-09 14:31 | 2026-08-07 03:11 |
| GHSA-775G-4XR8-78H8 CVE-2026-41849 | Spring Framework Denial of Service via Integer Overflow in SpEL Expressions | 高危 | Mavenorg.springframework:spring-expression | 已审查 | 2026-06-09 14:31 | 2026-07-31 00:52 |
| GHSA-659M-PX2C-25WJ CVE-2026-41848 | Spring Framework Denial of Service via AntPathMatcher | 低危 | Mavenorg.springframework:spring-core | 已审查 | 2026-06-09 14:31 | 2026-07-31 02:29 |
| GHSA-X23C-287F-QQV5 CVE-2026-41842 | Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux | 高危 | Mavenorg.springframework:spring-webflux+1 | 已审查 | 2026-06-09 14:31 | 2026-07-30 23:27 |
| GHSA-Q723-847Q-5G8G CVE-2026-41838 | Spring Framework Predictable Session ID in WebSocket Module | 中危 | Mavenorg.springframework:spring-websocket | 已审查 | 2026-06-09 14:31 | 2026-07-30 02:08 |
| GHSA-PFC9-2CQG-9WQ6 CVE-2026-41715 | Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect | 中危 | Mavenio.projectreactor.netty:reactor-netty | 已审查 | 2026-06-09 14:31 | 2026-07-30 02:18 |
| GHSA-MQ64-J8F9-9GCJ CVE-2026-41841 | Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux | 中危 | Mavenorg.springframework:spring-webflux+1 | 已审查 | 2026-06-09 14:31 | 2026-07-30 23:24 |
| GHSA-JRV5-8W28-4265 CVE-2026-41720 | Spring LDAP has Authentication Bypass with Empty Password | 高危 | Mavenorg.springframework.ldap:spring-ldap-core | 已审查 | 2026-06-09 14:31 | 2026-07-30 02:15 |
| GHSA-H3QP-GQRC-Q736 CVE-2026-41844 | Spring Framework Open Redirect in Spring MVC and WebFlux | 中危 | Mavenorg.springframework:spring-webflux+1 | 已审查 | 2026-06-09 14:31 | 2026-07-31 02:06 |
| GHSA-83F7-V6PX-PP3H CVE-2026-41840 | Spring Framework Denial of Service via Multipart Requests in WebFlux | 中危 | Mavenorg.springframework:spring-webflux | 已审查 | 2026-06-09 14:31 | 2026-07-30 23:20 |
| GHSA-7FXC-486F-32Q9 CVE-2026-41006 | Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration | 高危 | Mavenorg.springframework.hateoas:spring-hateoas | 已审查 | 2026-06-09 14:31 | 2026-07-30 02:02 |
| GHSA-72PG-X5F8-J25J CVE-2026-41843 | Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux | 中危 | Mavenorg.springframework:spring-webflux+1 | 已审查 | 2026-06-09 14:31 | 2026-07-30 23:49 |
| GHSA-4HFH-6X8G-GWPP CVE-2026-41839 | Spring Framework Escalation via Session Fixation in WebFlux | 中危 | Mavenorg.springframework:spring-webflux | 已审查 | 2026-06-09 14:31 | 2026-07-30 23:16 |
| GHSA-439X-6767-44CV CVE-2026-41007 | Spring HATEOAS heap exhaustion through unbounded internal caching | 高危 | Mavenorg.springframework.hateoas:spring-hateoas | 已审查 | 2026-06-09 14:31 | 2026-07-30 02:06 |
| GHSA-3CHG-M5W7-QFV5 CVE-2026-41845 | Spring Framework Cross-site Scripting via JavaScriptUtils | 高危 | Mavenorg.springframework:spring-webmvc | 已审查 | 2026-06-09 14:31 | 2026-07-31 00:55 |
| GHSA-2827-2MXX-J8PV CVE-2026-41710 | Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service | 中危 | Mavenorg.springframework.retry:spring-retry | 已审查 | 2026-06-09 14:31 | 2026-07-30 02:10 |
| GHSA-W737-WX49-QJ23 CVE-2026-40983 | Micrometer gRPC server instrumentation DoS | 高危 | Mavenio.micrometer:micrometer-core | 已审查 | 2026-06-09 14:31 | 2026-09-02 23:34 |
| GHSA-G3PR-3P32-FP23 CVE-2026-40984 | Micrometer HTTP server instrumentations DoS | 高危 | Mavenio.micrometer:micrometer-core+2 | 已审查 | 2026-06-09 14:31 | 2026-09-02 23:34 |
| GHSA-2VQW-3MP8-CGMX CVE-2026-47737 | Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections | 高危 | RubyGemspuma | 已审查 | 2026-06-09 08:09 | 2026-06-09 08:09 |