Spring Messaging
org.springframework:spring-messaging has critical vulnerabilities — do not use
Update to >= 5.2.22.RELEASE to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| critical | CVE-2018-1275 | Spring Framework has Improperly Implemented Security Check for Standard | 5.0.5.RELEASE |
| critical | CVE-2018-1270 | Spring Framework allows applications to expose STOMP over WebSocket endpoints | 4.3.16.RELEASE |
| medium | CVE-2022-22971 | Allocation of Resources Without Limits or Throttling in Spring Framework | 5.2.22.RELEASE |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/maven/org.springframework:spring-messagingLast updated · 2025-06-12T10:14:14+00:00