56,966 blogs · [ { "id": "01a0d8b0-a163-7151-8ceb-8024970d03d9", "title": "Spring AI 2.1.0-M1 Available Now", "url": "https://spring.io/blog/2026/09/25/spring-ai-2-1-0-M1-available-now", "published_at": "2026-09-25T00:00:00+00:00" }, { "id": "01a0d8b0-a163-7151-8ceb-802497212dc7", "title": "Spring Boot 4.2.0-M2 available now", "url": "https://spring.io/blog/2026/09/25/spring-boot-4-2-0-M2-available-now", "published_at": "2026-09-25T00:00:00+00:00" }, { "id": "01a0d8b0-a163-7151-8ceb-80249772424c", "title": "Spring Batch 6.1.0-M2 is out!", "url": "https://spring.io/blog/2026/09/24/spring-batch-6", "published_at": "2026-09-24T00:00:00+00:00" }, { "id": "01a0d8b0-a163-7151-8ceb-80249859a264", "title": "Spring Cloud 2026.0.0-M1 (aka Paddington) Has Been Released", "url": "https://spring.io/blog/2026/09/24/spring-cloud-2026-0-0-M1-has-been-released", "published_at": "2026-09-24T00:00:00+00:00" }, { "id": "01a0d8b0-a163-7151-8ceb-80249862400d", "title": "A Bootiful Podcast: Michael Carducci on optimizing data for agentic workflows", "url": "https://spring.io/blog/2026/09/24/a-bootiful-podcast-michael-carducci", "published_at": "2026-09-24T00:00:00+00:00" }, { "id": "01a0d8b0-a163-7151-8ceb-80249955a71e", "title": "This Week in Spring - September 22nd, 2026", "url": "https://spring.io/blog/2026/09/22/this-week-in-spring-september-22-2026", "published_at": "2026-09-22T00:00:00+00:00" }, { "id": "01a0c515-5a47-7331-ac62-4dba5dcf0733", "title": "Spring AI and TypeSafe Jev: Fast, Cheap, Structured Decisions", "url": "https://spring.io/blog/2026/09/21/spring-ai-typesafe-structured-judgment", "published_at": "2026-09-21T00:00:00+00:00" }, { "id": "01a0c515-5a47-7331-ac62-4dba5dff2782", "title": "Releasing Spring for Modern Challenges", "url": "https://spring.io/blog/2026/09/21/releasing-spring-for-modern-challenges", "published_at": "2026-09-21T00:00:00+00:00" }, { "id": "01a0b877-1291-705e-8fe3-69b7803959f9", "title": "A Bootiful Podcast: Spring Tools lead Martin Lippert", "url": "https://spring.io/blog/2026/09/17/a-bootiful-podcast-martin-lippert", "published_at": "2026-09-17T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a50539f14", "title": "Spring Office Hours Podcast: S5E23 - Java 27 Release Party with Billy Korando", "url": "https://spring.io/blog/2026/09/16/spring-office-hours-podcast-S5E23", "published_at": "2026-09-16T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5118d4ab", "title": "This Week in Spring - September 15th, 2026", "url": "https://spring.io/blog/2026/09/15/this-week-in-spring-september-15th-2026", "published_at": "2026-09-15T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a51e30aef", "title": "A Bootiful Podcast: Netflix's Paul Bakker", "url": "https://spring.io/blog/2026/09/10/a-bootiful-podcast-paul-bakker", "published_at": "2026-09-10T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a53b34601", "title": "Spring Tools 5.4.0 released", "url": "https://spring.io/blog/2026/09/09/spring-tools-5-4-0-released", "published_at": "2026-09-09T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a53da8d83", "title": "Spring Modulith 2.2 M1, 2.1.1, 2.0.8, and 1.4.13 released", "url": "https://spring.io/blog/2026/08/26/spring-modulith-2-2-m1-2-1-1-2-0-8-and-1-4-13-released", "published_at": "2026-08-26T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a53e013c0", "title": "Spring AI 2.0.1 Available Now", "url": "https://spring.io/blog/2026/08/21/spring-ai-2-0-1-available-now", "published_at": "2026-08-21T00:00:00+00:00" }, { "id": "01a0b5e7-7526-7354-8345-52f193a24fc8", "title": "cve-2026-47879 - HIGH - Spring Cloud Gateway SSRF and native file access with gRPC", "url": "https://spring.io/security/cve-2026-47879", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b844-20cb-7328-b59a-2153ad440544", "title": "cve-2026-59282 - MEDIUM - Spring Framework Denial of Service via Unbounded List Growth in Data Binding", "url": "https://spring.io/security/cve-2026-59282", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b844-20cb-7328-b59a-2153ad809de3", "title": "cve-2026-59281 - MEDIUM - Spring Framework Cross-site Scripting via EscapedErrors", "url": "https://spring.io/security/cve-2026-59281", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5411fd43", "title": "Spring Batch 6.0.5 and 6.1.0-M1 available now", "url": "https://spring.io/blog/2026/08/20/spring-batch-6-0-5-and-6-1-0-M1-available-now", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a547a7fc6", "title": "cve-2026-41707 - HIGH - Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay", "url": "https://spring.io/security/cve-2026-41707", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a547ccf8d", "title": "cve-2026-47834 - MEDIUM - Spring Data JPA Sort expression validation bypass", "url": "https://spring.io/security/cve-2026-47834", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a54858cb0", "title": "cve-2026-47836 - HIGH - Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN", "url": "https://spring.io/security/cve-2026-47836", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a54dbb7d6", "title": "cve-2026-47837 - MEDIUM - Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests", "url": "https://spring.io/security/cve-2026-47837", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a55d0699e", "title": "cve-2026-47841 - HIGH - WebAuthn User Verification Bypass via Session Serialization", "url": "https://spring.io/security/cve-2026-47841", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a56256051", "title": "cve-2026-47842 - MEDIUM - Deterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows Ciphertext Correlation", "url": "https://spring.io/security/cve-2026-47842", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a566ebd39", "title": "cve-2026-47843 - LOW - Reactor Netty may incorrectly route traffic due to DNS resolver reuse", "url": "https://spring.io/security/cve-2026-47843", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5690b77f", "title": "cve-2026-47844 - MEDIUM - Reactor Netty HTTP Server Leaks Exception Details", "url": "https://spring.io/security/cve-2026-47844", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5703e399", "title": "cve-2026-47845 - MEDIUM - Reactor Netty HTTP Server may incorrectly evaluate proxy addresses", "url": "https://spring.io/security/cve-2026-47845", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5783a40d", "title": "cve-2026-47848 - MEDIUM - Reactor Netty WebSocket Client Leaks Credentials On Redirect", "url": "https://spring.io/security/cve-2026-47848", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a578e1976", "title": "cve-2026-47849 - HIGH - Spring Data REST allows mutation of identifier and version properties via JSON Patch", "url": "https://spring.io/security/cve-2026-47849", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a57b2c85f", "title": "cve-2026-47850 - MEDIUM - Spring Data REST allows mutation of the version property of immutable aggregates via PUT", "url": "https://spring.io/security/cve-2026-47850", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a58a5588b", "title": "cve-2026-47851 - HIGH - Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader", "url": "https://spring.io/security/cve-2026-47851", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a59406a1f", "title": "cve-2026-47852 - HIGH - Predictable cache directory location allows local ONNX model substitution in Spring AI", "url": "https://spring.io/security/cve-2026-47852", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a59495cac", "title": "cve-2026-47856 - MEDIUM - JsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-list", "url": "https://spring.io/security/cve-2026-47856", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5a2f39dd", "title": "cve-2026-47857 - MEDIUM - Reactor Core windowTimeout fair-backpressure stream hang due to 20-bit index wrap-around", "url": "https://spring.io/security/cve-2026-47857", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5a39ba21", "title": "cve-2026-47859 - MEDIUM - Unbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoS", "url": "https://spring.io/security/cve-2026-47859", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5afcc5e7", "title": "cve-2026-47860 - MEDIUM - Unbounded decompression of attacker-supplied compressed message bodies", "url": "https://spring.io/security/cve-2026-47860", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5b50fb64", "title": "cve-2026-47861 - MEDIUM - UDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when acknowledge=false", "url": "https://spring.io/security/cve-2026-47861", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5bac906e", "title": "cve-2026-47863 - MEDIUM - Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream delivers items during an active flush", "url": "https://spring.io/security/cve-2026-47863", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5c56043b", "title": "cve-2026-47864 - MEDIUM - Unsafe Java deserialization in SerializingHttpMessageConverter — remote code execution", "url": "https://spring.io/security/cve-2026-47864", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5cf12c43", "title": "cve-2026-47862 - MEDIUM - ZipTransformer uses file_name header to build workDirectory path without sanitization", "url": "https://spring.io/security/cve-2026-47862", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5d9ab487", "title": "cve-2026-47875 - MEDIUM - JobParameterDeserializer bypasses the trusted-type allowlist", "url": "https://spring.io/security/cve-2026-47875", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5e729b53", "title": "cve-2026-47877 - HIGH - Spring Security Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS)", "url": "https://spring.io/security/cve-2026-47877", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5e7c0916", "title": "cve-2026-47878 - MEDIUM - Unsafe Java deserialization in DefaultExecutionContextSerializer without class allowlist", "url": "https://spring.io/security/cve-2026-47878", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5f787971", "title": "cve-2026-47874 - MEDIUM - Reactor Netty HTTP Server Denial of Service With Pipelined Requests", "url": "https://spring.io/security/cve-2026-47874", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5fdeceb6", "title": "cve-2026-47881 - MEDIUM - Denial of Service in Spring Batch FlatFileItemReader via Malformed Input File", "url": "https://spring.io/security/cve-2026-47881", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5fedc20e", "title": "cve-2026-47883 - MEDIUM - Spring Framework Open Redirect in UrlHandlerFilter", "url": "https://spring.io/security/cve-2026-47883", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a606fc885", "title": "cve-2026-47884 - MEDIUM - Spring Framework Improper Path Limitation in XsltView", "url": "https://spring.io/security/cve-2026-47884", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a608ef4ab", "title": "cve-2026-47880 - MEDIUM - DefaultJmsHeaderMapper copies all JMS user properties into MessageHeaders without excluding framework-significant names", "url": "https://spring.io/security/cve-2026-47880", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a6180ca7a", "title": "cve-2026-47885 - MEDIUM - Spring Framework maxPartSize Ignored in PartEventHttpMessageReader", "url": "https://spring.io/security/cve-2026-47885", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a6224acf8", "title": "cve-2026-47886 - MEDIUM - Spring Framework Denial of Service via Unbounded Exponentiation in SpEL Expressions", "url": "https://spring.io/security/cve-2026-47886", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a62ac8984", "title": "cve-2026-47887 - MEDIUM - Spring Framework Open Redirect in UrlFileNameViewController", "url": "https://spring.io/security/cve-2026-47887", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a6332e7f0", "title": "cve-2026-47888 - MEDIUM - Spring Framework Memory Leak via SETUP Frame in RSocketMessageHandler", "url": "https://spring.io/security/cve-2026-47888", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a64263e74", "title": "cve-2026-47889 - MEDIUM - Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse", "url": "https://spring.io/security/cve-2026-47889", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a6448ebf5", "title": "cve-2026-47890 - LOW - Spring Framework Server Sent Event stream corruption while rendering fragments", "url": "https://spring.io/security/cve-2026-47890", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a64aef49f", "title": "cve-2026-47892 - MEDIUM - Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints", "url": "https://spring.io/security/cve-2026-47892", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a6502f744", "title": "cve-2026-47893 - LOW - Spring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketService", "url": "https://spring.io/security/cve-2026-47893", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a654a0739", "title": "cve-2026-47894 - MEDIUM - Spring Cloud Config Server Native Environment Repository Exposure", "url": "https://spring.io/security/cve-2026-47894", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a657e8235", "title": "cve-2026-59270 - CRITICAL - Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces", "url": "https://spring.io/security/cve-2026-59270", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a65e4aeef", "title": "cve-2026-59271 - MEDIUM - Admin password disclosed in BrokerNotAliveException message", "url": "https://spring.io/security/cve-2026-59271", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a66b4ac3f", "title": "cve-2026-47891 - MEDIUM - Spring Framework maxInMemorySize Bypassed in Jaxb2Decoder", "url": "https://spring.io/security/cve-2026-47891", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a67876b68", "title": "cve-2026-59272 - MEDIUM - Log4j2 AmqpAppender disables TLS hostname verification by default", "url": "https://spring.io/security/cve-2026-59272", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a67e6d26a", "title": "cve-2026-59274 - MEDIUM - Unbounded decompression in UnZipTransformer enables zip-bomb DoS", "url": "https://spring.io/security/cve-2026-59274", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a67fab34f", "title": "cve-2026-59275 - MEDIUM - Remote JVM termination: nested-array Java deserialization bypasses allowlist, triggers StackOverflowError, default JavaLangErrorHandler calls System.exit(99)", "url": "https://spring.io/security/cve-2026-59275", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a68dd8ffe", "title": "cve-2026-59278 - MEDIUM - In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types in header mapper default trusted packages", "url": "https://spring.io/security/cve-2026-59278", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a690a84aa", "title": "cve-2026-59279 - HIGH - Unbounded persistent session allocation via repeated initialize requests", "url": "https://spring.io/security/cve-2026-59279", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a697cfe2d", "title": "cve-2026-59280 - MEDIUM - Spring Framework Path Traversal via Backslash in SpringTemplateLoader", "url": "https://spring.io/security/cve-2026-59280", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a69c066b4", "title": "cve-2026-59276 - MEDIUM - Timing Attack via Non-Constant-Time Comparison of Sensitive Values", "url": "https://spring.io/security/cve-2026-59276", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a6a0408fe", "title": "cve-2026-59277 - LOW - Spring Security InetAddressMatchers Incomplete Internal Network Classification", "url": "https://spring.io/security/cve-2026-59277", "published_at": "2026-08-20T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a52722459", "title": "A New Home for Spring Cloud Contract: Transitioning to Stubborn.sh", "url": "https://spring.io/blog/2026/07/06/spring-cloud-contract-transition-to-stubbornsh", "published_at": "2026-07-06T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a528abb18", "title": "Spring and Security In The Times Of AI", "url": "https://spring.io/blog/2026/06/01/spring_and_security_in_the_times_of_ai", "published_at": "2026-06-01T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a52b6a111", "title": "May Release Train Date Changes", "url": "https://spring.io/blog/2026/05/11/may-train-shift", "published_at": "2026-05-11T00:00:00+00:00" }, { "id": "01a0b877-1292-7223-8ea7-873a5393f3f3", "title": "Catch the Spring Team at Spring I/O 2026!", "url": "https://spring.io/blog/2026/04/10/spring-io-2026-broadcom-speakers", "published_at": "2026-04-10T00:00:00+00:00" } ] posts Claim your blog
Back to spring.io
Blog · corpus.blog/blogs/spring.io/posts

spring.io

spring.io

2026