Spring Web
93%
Total Score
100
97
80
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-620042 New spring-web is vulnerable to HTTP Request/Response Splitting in versions 0.0.1 - 7.0.8. | 0.0.1 - 7.0.8 | Low |
CVE-2026-41854 org.springframework:spring-web is vulnerable to Server-Side Request Forgery (SSRF) in versions 7.0.0 - 7.0.7 and 6.2.0 - 6.2.18. | 6.2.0 - 6.2.187.0.0 - 7.0.7 | Medium |
CVE-2025-41234 org.springframework:spring-web is vulnerable to Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in versions 6.2.0 - 6.2.8, 6.1.0 - 6.1.21 and 6.0.5 - 6.0.23. | 6.0.5 - 6.0.236.1.0 - 6.1.216.2.0 - 6.2.8 | Medium |
AIKIDO-2024-10361 spring-web is vulnerable to Improper Handling of Case Sensitivity in versions 0.0.1 - 5.3.40, 6.0.0 - 6.0.24 and 6.1.0 - 6.1.13. | 0.0.1 - 5.3.406.0.0 - 6.0.246.1.0 - 6.1.13 | Low |
CVE-2024-38809 org.springframework:spring-web is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 5.3.38, 6.0.0 - 6.0.23 and 6.1.0 - 6.1.12. | 0.0.0 - 5.3.386.0.0 - 6.0.236.1.0 - 6.1.12 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework:spring-beans Version 7.1.0-M1 | — | — |
org.springframework:spring-core Version 7.1.0-M1 | — | — |
io.micrometer:micrometer-observation Version 1.18.0-M1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant