Spring XML
97%
Total Score
98
86
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-400602 spring-xml is vulnerable to XML External Entity (XXE) Attack in versions 0.0.1 - 3.1.8, 4.0.0 - 4.0.18, 4.1.0 - 4.1.3 and 5.0.0 - 5.0.1. | 0.0.1 - 3.1.84.0.0 - 4.0.184.1.0 - 4.1.3 +1 more | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
com.sun.xml.messaging.saaj:saaj-impl Version 3.0.5 | — | — |
jakarta.activation:jakarta.activation-api Version 2.1.4 | — | — |
jakarta.xml.soap:jakarta.xml.soap-api Version 3.0.2 | — | — |
org.springframework:spring-beans Version 7.0.8 | — | — |
org.springframework:spring-context Version 7.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant