Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.1VMware Updated

Low [CVE-2026-59306] Spring Cloud: Potential for deserialization of untrusted types in Spring Cloud Stream.

Potential for deserialization of untrusted types in Spring Cloud Stream.

CVE-2026-59306
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59305] Spring Cloud: Partition interceptor may be improperly added while sending message.

Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2

CVE-2026-59305
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59304] Spring Cloud: Improper caching of the original content type in Spring Cloud Stream Avro.

Improper caching of the original content type in Spring Cloud Stream Avro.

CVE-2026-59304
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59303] Spring Cloud: Dynamic destination cache size is not properly bound in Spring Cloud Stream.

Dynamic destination cache size is not properly bound in Spring Cloud Stream.

CVE-2026-59303
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59302] Spring Cloud: Potential for logging sensitive data in Spring Cloud Stream.

Potential for logging sensitive data in Spring Cloud Stream.

CVE-2026-59302
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59301] Spring Cloud: Potential for logging sensitive data in Spring Cloud Function Azure.

Potential for logging sensitive data in Spring Cloud Function Azure.

CVE-2026-59301
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59300] Spring Cloud: Potential for logging sensitive data in Spring Cloud Function AWS.

Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 3.2.16 and earlier

CVE-2026-59300
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59299] Spring Cloud: Composition lookup can potentially poison base function in Spring Cloud Function.

Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 3.2.16 and earlier

CVE-2026-59299
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59298] Spring Cloud: Potential for improper filtering of HTTP headers in Spring Cloud Function.

Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 3.2.16 and earlier

CVE-2026-59298
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59297] Spring Cloud: Implementation of isSecure call of ServerlessHttpServletRequest does not verify the actual scheme.

Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3

CVE-2026-59297
Tanzu / Spring
Aug 27, 2026
Low2.0VMware Updated

Low [CVE-2026-59291] Spring Cloud: Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.

Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.

CVE-2026-59291
Tanzu / Spring
Aug 27, 2026
Low3.7VMware Updated

Low [CVE-2026-59277] Spring Security: Spring Security's InetAddressMatchers utility provides matchInternal and matchExternal builders for constructing…

Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or external (public) network.

CVE-2026-59277
Tanzu / Spring
Aug 27, 2026
Low2.7VMware

Low [CVE-2026-41709] ESX insufficient logging vulnerability

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.

CVE-2026-41709
ESXiCloud FoundationvSphere
Jul 30, 2026
Low3.3VMware

Low [CVE-2026-59326] Spring Boot: The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment v…

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-59326
Tanzu / Spring
Jul 30, 2026
Low3.8VMware

Low [CVE-2026-59269] user authenticating to Kubernetes clusters via the Pinniped Supervisor

A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions were true: the Pinniped Supervisor server is running with an ActiveDirectoryIdentityProvider resource configured; the ActiveDirectoryIdentityProvider.spec.groupSearch.attributes.groupName is empty; the attacker gains the ability to edit some part of the distinguished name (DN) of group entries in the Active Directory (AD) server's database for groups to which they belong; the configured group search parameters cause the edited group to be included in the group search results for the user; and the attacker knows the password for an AD user who belongs to the edited AD group. Affected versions: Pinniped (go.pinniped.dev) v0.11.0 through v0.46.0 inclusive; fixed in v0.47.0.

CVE-2026-59269
Unclassified
Jul 9, 2026
Low3.7VMware

Low [CVE-2026-41000] Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp elements, and certain SAML one-time-use semantics could be ineffective even when operators configured a replay cache on the interceptor. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

CVE-2026-41000
Unclassified
Jun 11, 2026
Low3.7VMware

Low [CVE-2026-41694] Spring Security: Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses wit…

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-41694
Tanzu / Spring
Jun 10, 2026