vendor

vmware

18 thingsrelated by NVD
Severity
Exploited

Its products

spring framework 7 spring ai 3 spring cloud gateway 2 cloud foundation 1 spring advanced message queuing protocol 1 spring cloud function 1 spring integration 1 spring security 1 vrealize operations manager 1 vrealize suite lifecycle manager 1 workspace one uem console 1

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a…
CVE-2026-59318
Severity critical
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow…
CVE-2026-59308
Severity medium
Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring…
CVE-2026-59302
Severity medium
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and…
CVE-2026-59279
Severity high
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring…
CVE-2026-47889
Severity high
Spring Framework: Spring Framework: Memory leak via malformed RSocket SETUP frame
CVE-2026-47888
Severity high
org.springframework/spring-webmvc: Spring Framework: Open redirect vulnerability in UrlFileNameViewController
CVE-2026-47887
Severity medium
Spring Framework: org.springframework/spring-expression: Spring Framework: Denial of Service via unbounded exponentiation in SpEL…
CVE-2026-47886
Severity high
org.springframework/spring-webflux: Spring WebFlux: Denial of Service via ignored maxPartSize limit
CVE-2026-47885
Severity high
org.springframework/spring-webmvc: Spring Framework: Remote Code Execution via improper path limitation in XsltView
CVE-2026-47884
Severity critical
org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring Framework: Open redirect vulnerability in UrlHandlerFilter…
CVE-2026-47883
Severity medium
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties…
CVE-2026-47880
Severity medium
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring…
CVE-2026-47879
Severity high
spring-cloud-gateway: Spring Cloud Gateway Server: Security bypass due to untrusted header forwarding
CVE-2026-47825
Severity high
org.springframework.security/spring-security-oauth2-client: Spring Security: DPoP Proof Replay via Cache Eviction
CVE-2026-41707
Severity high
Spring AMQP: Spring AMQP: Predictable correlation IDs may lead to information disclosure
CVE-2026-41701
Severity medium
Omnissa Workspace ONE Server-Side Request Forgery
CVE-2021-22054
Severity high Exploited yes
VMware Server Side Request Forgery in vRealize Operations Manager API
CVE-2021-21975
Severity high Exploited yes