Security Update Advisory for Spring Products

Security Update Advisory for Spring Products

Overview

A security update has been released to address vulnerabilities in Spring products. Users of these products should update to the latest version.

Affected Products and Vulnerabilities

  • CVE-2026-47858: This affects Spring Tools for Eclipse version 5.2.0 Or earlier, Spring Tools for VSCode version 2.2.0 Or earlier, Spring Tools for Cursor version 2.2.0 Or earlier, and Spring Tools for Theia version 2.2.0 Or earlier.
  • CVE-2026-47873, CVE-2026-47882: Affects Spring Tools for Eclipse version 5.2.0 Or earlier.

Resolved Vulnerabilities

  • CVE-2026-47858: A JMX (Java Management Extensions, remote management functionality)-based remote code execution vulnerability occurring in Spring Tools’ Live Information mode.
  • CVE-2026-47873: An unauthenticated JDWP (Java Debug Wire Protocol) and JMX port exposure vulnerability in Spring Tools for Eclipse.
  • CVE-2026-47882: A vulnerability in Spring Tools for Eclipse that allows remote secret generation in Spring Boot DevTools.

Versions Affected by the Vulnerability Patch

  • CVE-2026-47858: You must update to Spring Tools for Eclipse 5.3.0 Or later, Spring Tools for VSCode 2.3.0 Or later, Spring Tools for Cursor 2.3.0 Or later, or Spring Tools for Theia 2.3.0 Or later.
  • CVE-2026-47873, CVE-2026-47882: You must update to Spring Tools for Eclipse 5.3.0 Or later.

Note

Vulnerability Patches have been provided in the latest updates; you must update to the patched versions as instructed on the reference sites.