VMware (Broadcom) Security Advisories & CVEs
71 advisories tracked · VMware Security Advisories (VMSA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor VMware CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your VMware device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in VMware's recent advisories.
Official source
VMware Security Advisories (VMSA) via NVD
Broadcom's VMSA portal is a JavaScript app with no stable public feed, so VulniPulse ingests VMware CVEs from NVD filtered to VMware's own CNAs (security@vmware.com and Broadcom's successor CNA) — official, CNA-published data covering ESXi, vCenter Server, NSX, Aria/vRealize, Cloud Foundation, Workstation/Fusion and VMware Tools. Each entry links back to the Broadcom/VMware advisory when NVD carries the reference.
Latest VMware advisories
Medium [CVE-2026-41711] Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException
Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.
Medium [CVE-2026-41706] Spring Security: Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a brows…
Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute URL is stored in the cookie and is used without validation as the post-login redirect target. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
Medium [CVE-2026-41701] Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable
Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.
Medium [CVE-2026-41697] Spring Data Relational does not properly escape binding values of externally-controlled input
Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An attacker can supply wildcard characters to perform boolean-based blind data inference. Affected versions: Spring Data Relational/JDBC/R2DBC 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.4.0 through 2.4.19.
Medium [CVE-2026-41696] Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient…
Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expression quoting. Affected versions: Spring Data MongoDB 5.0.0 through 5.0.5; 4.5.0 through 4.5.11; 4.4.0 through 4.4.14; 4.3.0 through 4.3.16; 4.2.0 through 4.2.15; 4.1.0 through 4.1.14; 4.0.0 through 4.0.15; 3.4.0 through 3.4.19.
Medium [CVE-2026-41008] Spring Security: Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri par…
Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability. Affected versions: Spring Security 7.0.0 through 7.0.5.
Medium [CVE-2026-40991] When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker…
When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed. Affected versions: Spring REST Docs 4.0.0; 3.0.0 through 3.0.5; 2.0.0.RELEASE through 2.0.8.RELEASE.
Medium [CVE-2026-41854] Spring Framework: Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally pro…
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
Medium [CVE-2026-41853] Spring Framework: Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Medium [CVE-2026-41851] Spring Framework: Applications which accept user-supplied Spring Expression Language (SpEL) expressions
Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected product named by the advisory: Spring Framework.
Medium [CVE-2026-41847] Spring Framework: Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected product named by the advisory: Spring Framework.
Medium [CVE-2026-41846] Spring Framework: Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected product named by the advisory: Spring Framework.
Medium [CVE-2026-41844] Spring Framework: Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified
A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected product named by the advisory: Spring Framework.
Medium [CVE-2026-41843] Spring Framework: Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources.
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected product named by the advisory: Spring Framework.
Medium [CVE-2026-41841] Spring Framework: Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources.
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected product named by the advisory: Spring Framework.
Medium [CVE-2026-41840] Spring Framework: Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
Medium [CVE-2026-41839] Spring Framework: WebFlux application with a compromised subdomain (for example, compromised
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected product named by the advisory: Spring Framework.
Medium [CVE-2026-41838] Spring Framework: IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which
IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected product named by the advisory: Spring Framework.
Medium [CVE-2026-41715] In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client
In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
Medium [CVE-2026-41710] attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide…
An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in the application to fail.