Spring Web MVC
org.springframework:spring-webmvc has critical vulnerabilities — do not use
Update to >= 5.3.42 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2016-9878 | Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized | 4.3.5 |
| critical | CVE-2022-22965 | Remote Code Execution in Spring Framework | 2.6.6 |
| medium | CVE-2026-22737 | Spring Framework Improper Path Limitation with Script View Templates | 6.2.17 |
| low | CVE-2026-22735 | Spring MVC and WebFlux has Server Sent Event stream corruption | 6.2.17 |
| critical | CVE-2023-20860 | Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch | 5.3.26 |
| medium | CVE-2020-5397 | CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux | 5.2.3 |
| medium | CVE-2014-0054 | Cross-Site Request Forgery in Spring Framework | 4.0.2 |
| high | CVE-2020-5398 | RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application | 5.0.16.RELEASE |
| high | CVE-2024-38816 | Path traversal vulnerability in functional web frameworks | 6.1.13 |
| high | CVE-2014-0225 | Improper Restriction of XML External Entity Reference in Spring Framework | 3.2.8 |
| medium | CVE-2014-1904 | Improper Neutralization of Input During Web Page Generation in Spring Framework | 4.0.2.RELEASE |
| high | CVE-2024-38819 | Spring Framework Path Traversal vulnerability | 6.1.14 |
| medium | CVE-2014-3625 | Improper Limitation of a Pathname to a Restricted Directory in Spring Framework | 4.1.2 |
| medium | CVE-2025-41242 | Spring Framework MVC Applications Path Traversal Vulnerability | 6.2.10 |
| high | CVE-2023-34053 | Spring Framework vulnerable to denial of service | 6.0.14 |
| medium | CVE-2024-38828 | Spring MVC controller vulnerable to a DoS attack | 5.3.42 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/maven/org.springframework:spring-webmvcLast updated · 2025-06-12T10:14:08+00:00