vmware / spring_boot
9 known vulnerabilities in vmware spring_boot.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-40976 | Medium | 0.5% | 9.1 | In certain circumstances, Spring Boot's default web security is ineffective allo… | |
| CVE-2026-40972 | Medium | 0.3% | 7.5 | An attacker on the same network as the remote application may be able to utilize… | |
| CVE-2026-40973 | Medium | 0.1% | 7.0 | A local attacker on the same host as the application may be able to take control… | |
| CVE-2026-40975 | Low | 0.3% | 4.8 | Values produced by ${random.value} are not suitable for use as secrets. ${random… | |
| CVE-2026-40974 | Low | 0.2% | 5.0 | Spring Boot's Cassandra auto-configuration does not perform hostname verificatio… | |
| CVE-2026-40971 | Low | 0.2% | 5.0 | When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration … | |
| CVE-2026-40992 | Low | 0.1% | 5.0 | Spring Boot's Mail auto-configuration does not enable hostname verification. App… | |
| CVE-2026-40977 | Low | 0.1% | 4.7 | When an application is configured to use `ApplicationPidFileWriter`, a local att… | |
| CVE-2026-41001 | Low | 0.1% | 5.3 | Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for … |