Spring Product Security Update Advisory (CVE-2026-41862)

Spring Product Security Update Advisory (CVE-2026-41862)

Overview A security update has been released to address a vulnerability in Spring products. The vulnerability is CVE-2026-41862, a deserialization vulnerability (the process of converting stored data back into an object) in Spring StateMachine. Affected Products Spring Statemachine 4.0.0 Through 4.0.1. Spring Statemachine 3.2.0 Through 3.2.4. Fixed Versions Spring StateMachine

Spring Product Security Update Advisory (CVE-2026-41842)

Spring Product Security Update Advisory (CVE-2026-41842)

Overview A security update has been released to address a vulnerability in Spring products. The vulnerability is a denial-of-service (DoS) vulnerability in the Spring Framework, identified as CVE-2026-41842. Affected Products Spring Framework 7.0.0 through 7.0.7. Spring Framework 6.2.0 through 6.2.18. Spring Framework 6.1.0 through 6.1.27. Spring Framework 5.3.0 through 5.3.48.

Spring Product Security Update Advisory (CVE-2026-47838)

Spring Product Security Update Advisory (CVE-2026-47838)

Overview A security update has been released to address vulnerabilities in Spring products. Users of these products should update to the latest version. Affected Products and Scope of Impact Spring Security versions 5.7.0 through 5.7.24. Spring Security versions 5.8.0 through 5.8.26. Spring Security versions 6.3.0 through 6.3.17. Spring Security versions

Spring Product Security Update Advisory

Spring Product Security Update Advisory

Overview A security update has been released to address vulnerabilities found in Spring products. Environments using these products must be updated to the latest version with security patches. Affected Products and Vulnerabilities CVE-2026-41708: Denial-of-Service (DoS) vulnerability in Spring Cloud Sleuth. Affected Versions: 3.1.0 through 3.1.13. Fixed version: 3.1.14. CVE-2026-41838: Predictable

Spring Product Security Update Advisory

Spring Product Security Update Advisory

Security updates have been released to address multiple vulnerabilities in Spring products. the affected products are Micrometer, micrometer-core, micrometer-jetty11, micrometer-jetty12, Spring Integration, Spring Security, Spring Web Services, Spring HATEOAS, Spring Data Commons, Spring for GraphQL, Spring Data MongoDB, Spring LDAP, Spring Data REST, Spring for Apache Kafka, and Spring for

Spring Product Security Update Advisory

Spring Product Security Update Advisory

Overview A security update has been released to address a vulnerability in Spring products. the target is Spring AI, and users should update to the latest version. Affected Products and Versions Spring AI 1.0.0 and later, but earlier than 1.0.7. Spring AI 1.1.0 and later but earlier than 1.1.6. Resolved

Spring Product Security Update Advisory

Spring Product Security Update Advisory

Security updates have been released to address vulnerabilities in Spring products. the affected products are Spring Cloud Config and Spring AI. The vulnerabilities addressed in Spring Cloud Config are CVE-2026-40981, CVE-2026-40982, and CVE-2026-41002. CVE-2026-40981 is a privilege bypass vulnerability. CVE-2026-40982 is a Directory Path Manipulation vulnerability. CVE-2026-41002 is a TOCTOU

Spring Product Security Update Advisory (CVE-2026-40968)

Spring Product Security Update Advisory (CVE-2026-40968)

Security updates have been released for vulnerabilities in Spring products. the target is Spring gRPC versions 1.0.0 through 1.0.2 and earlier. the vulnerability is CVE-2026-40968, which is a request-to-request SecurityContext (a security state that holds authentication and authorization information) leak in Spring gRPC. the vulnerability occurs in the context of

Spring Product Security Update Advisory

Spring Product Security Update Advisory

Overview A security update has been released to address a vulnerability in Spring products. the target is Spring AI, and users should update to the latest version. Affected by Spring AI 1.0.0 or later and earlier than 1.0.6. Spring AI 1.1.0 and above, but below 1.1.5. Resolved vulnerabilities CVE-2026-40967: Failure

Spring Product Security Update Advisory

Spring Product Security Update Advisory

Overview A security update was released to address a vulnerability in Spring products. users of the affected products were advised to update to the latest version. Affected Products and Versions Spring Boot 4.0.0 or later and 4.0.5 or earlier. Spring Boot 3.5.0 or later and 3.5.13 or earlier. Spring Boot