| CVE-2026-59324 | high | 8.2 | When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emit… | Aug 27, 2026 | Sep 1, 2026 |
| CVE-2026-59322 | medium | 6.3 | The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its … | Aug 27, 2026 | Sep 1, 2026 |
| CVE-2026-59321 | medium | 4.2 | A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 e… | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-59320 | medium | 6.5 | When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery… | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-59319 | medium | 4.3 | RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-suppli… | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-59315 | medium | 5.3 | The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads.
… | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-59314 | low | 3.7 | Applications that build a Content-Disposition header value from untrusted input may be vulnerable to… | Aug 27, 2026 | Sep 1, 2026 |
| CVE-2026-59313 | critical | 9.8 | Spring MVC applications using the functional web framework are vulnerable to stream corruption when … | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-59311 | medium | 6.8 | A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a dire… | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-59307 | high | 8.0 | An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives … | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-59300 | low | 3.1 | Potential for logging sensitive data in Spring Cloud Function AWS.
Spring Cloud Function 5.0.0 - 5.0… | Aug 27, 2026 | Sep 2, 2026 |
| CVE-2026-59299 | low | 3.1 | Composition lookup can potentially poison base function in Spring Cloud Function.
Spring Cloud Funct… | Aug 27, 2026 | Sep 2, 2026 |
| CVE-2026-59298 | low | 3.1 | Potential for improper filtering of HTTP headers in Spring Cloud Function.
Spring Cloud Function 5.0… | Aug 27, 2026 | Sep 2, 2026 |
| CVE-2026-59297 | low | 3.1 | Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme.… | Aug 27, 2026 | Sep 2, 2026 |
| CVE-2026-59294 | medium | 5.9 | ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbat… | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-59293 | medium | 6.6 | Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1… | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-59292 | low | 3.2 | PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its stat… | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-59291 | low | 2.0 | Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.
Spring Cloud Function… | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-59289 | high | 7.5 | Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and for… | Aug 27, 2026 | Sep 2, 2026 |
| CVE-2026-59288 | high | 7.4 | The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the app… | Aug 27, 2026 | Sep 1, 2026 |
| CVE-2026-59287 | medium | 5.9 | Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with k… | Aug 27, 2026 | Sep 2, 2026 |
| CVE-2026-59286 | high | 8.1 | The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, with… | Aug 27, 2026 | Sep 2, 2026 |
| CVE-2026-59285 | high | 8.1 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated G… | Aug 27, 2026 | Sep 2, 2026 |
| CVE-2026-59283 | critical | 9.1 | Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationConte… | Aug 27, 2026 | Sep 1, 2026 |
| CVE-2026-59282 | high | 7.5 | Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied p… | Aug 27, 2026 | Sep 2, 2026 |