Known Vulnerabilities for Spring Boot by Vmware
Listed below are 10 of the newest known vulnerabilities associated with "Spring Boot" by "Vmware".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-50201 json | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. ... | Not Provided | 2026-06-17 | 2026-06-18 |
| CVE-2026-45091 json | sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-44308 json | Spring Cloud AWS simplifies using AWS managed services in a Spring and Spring Boot applications. From 3.0.0 to 4.0.1, pplicat... | Not Provided | 2026-05-14 | 2026-05-14 |
| CVE-2026-41001 json | Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data di... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-40992 json | Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail prop... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-40977 json | When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's loc... | Not Provided | 2026-04-28 | 2026-04-28 |
| CVE-2026-40976 json | In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. Fo... | Not Provided | 2026-04-28 | 2026-04-29 |
| CVE-2026-40975 json | Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${r... | Not Provided | 2026-04-28 | 2026-04-28 |
| CVE-2026-40974 json | Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cass... | Not Provided | 2026-04-28 | 2026-04-28 |
| CVE-2026-40973 json | A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. ... | Not Provided | 2026-04-28 | 2026-04-29 |