Spring Core
99%
Total Score
99
94
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11158 spring-core is vulnerable to Cross-site Scripting (XSS) in versions 5.3.0 - 5.3.48, 6.1.0 - 6.1.27, 6.2.0 - 6.2.18 and 7.0.0 - 7.0.7. | 5.3.0 - 5.3.486.1.0 - 6.1.276.2.0 - 6.2.18 +1 more | High |
AIKIDO-2026-10571 spring-core is vulnerable to Unlimited Resource Consumption in versions 1.0.0 - 5.3.47, 6.0.0 - 6.1.26, 6.2.0 - 6.2.17 and 7.0.0 - 7.0.6. | 1.0.0 - 5.3.476.0.0 - 6.1.266.2.0 - 6.2.17 +1 more | Medium |
CVE-2025-41249 org.springframework:spring-core is vulnerable to Improper Authorization in versions 5.3.0 - 5.3.44, 6.0.0 - 6.1.22 and 6.2.0 - 6.2.10. | 5.3.0 - 5.3.446.0.0 - 6.1.226.2.0 - 6.2.10 | High |
AIKIDO-2024-10363 spring-core is vulnerable to Improper Handling of Case Sensitivity in versions 0.0.1 - 5.3.40, 6.0.0 - 6.0.24 and 6.1.0 - 6.1.13. | 0.0.1 - 5.3.406.0.0 - 6.0.246.1.0 - 6.1.13 | Low |
CVE-2024-22233 org.springframework:spring-core is vulnerable to Uncontrolled Resource Consumption in versions 6.1.2 - 6.1.2 and 6.0.15 - 6.0.15. | 6.0.15 - 6.0.156.1.2 - 6.1.2 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
commons-logging:commons-logging Version 1.3.5 | — | — |
org.jspecify:jspecify Version 1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant