Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-59306] Spring Cloud: Potential for deserialization of untrusted types in Spring Cloud Stream.
Potential for deserialization of untrusted types in Spring Cloud Stream.
Low [CVE-2026-59305] Spring Cloud: Partition interceptor may be improperly added while sending message.
Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2
Low [CVE-2026-59304] Spring Cloud: Improper caching of the original content type in Spring Cloud Stream Avro.
Improper caching of the original content type in Spring Cloud Stream Avro.
Low [CVE-2026-59303] Spring Cloud: Dynamic destination cache size is not properly bound in Spring Cloud Stream.
Dynamic destination cache size is not properly bound in Spring Cloud Stream.
Low [CVE-2026-59302] Spring Cloud: Potential for logging sensitive data in Spring Cloud Stream.
Potential for logging sensitive data in Spring Cloud Stream.
Low [CVE-2026-59301] Spring Cloud: Potential for logging sensitive data in Spring Cloud Function Azure.
Potential for logging sensitive data in Spring Cloud Function Azure.
Low [CVE-2026-59300] Spring Cloud: Potential for logging sensitive data in Spring Cloud Function AWS.
Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 3.2.16 and earlier
Low [CVE-2026-59299] Spring Cloud: Composition lookup can potentially poison base function in Spring Cloud Function.
Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 3.2.16 and earlier
Low [CVE-2026-59298] Spring Cloud: Potential for improper filtering of HTTP headers in Spring Cloud Function.
Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 3.2.16 and earlier
Low [CVE-2026-59297] Spring Cloud: Implementation of isSecure call of ServerlessHttpServletRequest does not verify the actual scheme.
Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3
Low [CVE-2026-59291] Spring Cloud: Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.
Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.
Low [CVE-2026-59277] Spring Security: Spring Security's InetAddressMatchers utility provides matchInternal and matchExternal builders for constructing…
Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or external (public) network.
Low [CVE-2025-71346] Heap buffer under-read in XML Schema validation
Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap-based buffer under-read (CVE-2025-32415) in the xmlSchemaIDCFillNodeTables function in xmlschemas.c. The issue can be triggered when validating against an untrusted XML Schema, or when validating untrusted documents against trusted schemas that use xsd:keyref in combination with recursively defined types that have additional identity constraints. Upstream and MITRE rate this issue as low severity. This heap-based buffer under-read vulnerability, located in the xmlSchemaIDCFillNodeTables function, can be triggered when processing untrusted XML Schemas or documents. A remote attacker could exploit this by providing specially crafted XML input, which may lead to unexpected application behavior or a limited denial of service (DoS). Red Hat severity: Low — CVSS 2.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6. Will not fix / out of support: Red Hat 3scale API Management Platform 2. Red Hat does not currently list a fixing RHSA for this CVE.