91 Vulnerabilities Patched in Spring Application Framework
The developers of Broadcom’s Spring application development framework last week announced the release of updates that patch 91 vulnerabilities.
Spring is an open source application framework for the Java platform that simplifies the creation of enterprise applications through features such as dependency injection, aspect-oriented programming, and modular support for web, data, and messaging architectures. After years under VMware’s stewardship, it transitioned to Broadcom following its acquisition of VMware.
A single vulnerability has been assigned a critical severity rating: CVE-2026-59270. It affects Spring Security’s embedded UnboundID LDAP server and could allow an attacker to authenticate and modify entries in the in-memory directory.
Over a dozen vulnerabilities have been classified as high severity. They can be exploited for XSS attacks, information disclosure, remote code execution, DoS attacks, security bypasses, and unauthorized access.
The remaining vulnerabilities have medium and low severity ratings.
Cybersecurity firm Sonatype has analyzedthe patches and found that...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE