Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
Maven/org.springframework.boot:spring-boot — 5 CVEs · VulnScope
pkg:Maven/
org.springframework.boot:spring-boot
5 total CVEs
CRITICAL
1
HIGH
3
MEDIUM
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.1
CVE-2026-40976
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
>= 4.0.0, < 4.0.6
HIGH
7.8
CVE-2022-27772
Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-boot
from 0, < 2.2.11.RELEASE
HIGH
7.3
CVE-2025-22235
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
from 0, <= 2.7.24.2
HIGH
7.0
Spring Boot accepts predictable temp directory without ownership verification
>= 4.0.0, < 4.0.6
MEDIUM
5.9
Moderate severity vulnerability that affects org.springframework.boot:spring-boot
>= 1.5.0, < 1.5.10
CVE-2026-40973
CVE-2018-1196