Spring WebFlux
99%
Total Score
99
97
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11150 spring-webflux is vulnerable to Protection Mechanism Failure in versions 5.3.0 - 5.3.48. | 5.3.0 - 5.3.48 | Medium |
AIKIDO-2026-11161 spring-webflux is vulnerable to Escalation via Session Fixation in WebFlux in versions 5.3.0 - 5.3.48, 6.1.0 - 6.1.27, 6.2.0 - 6.2.18 and 7.0.0 - 7.0.7. | 5.3.0 - 5.3.486.1.0 - 6.1.276.2.0 - 6.2.18 +1 more | Medium |
AIKIDO-2026-11160 spring-webflux is vulnerable to Open Redirect in versions 5.3.0 - 5.3.48, 6.1.0 - 6.1.27, 6.2.0 - 6.2.18 and 7.0.0 - 7.0.7. | 5.3.0 - 5.3.486.1.0 - 6.1.276.2.0 - 6.2.18 +1 more | Medium |
CVE-2026-22745 org.springframework:spring-webflux is vulnerable to Uncontrolled Resource Consumption in versions 7.0.0 - 7.0.6, 6.2.0 - 6.2.17, 6.1.0 - 6.1.26 and 0.0.0 - 5.3.47. | 0.0.0 - 5.3.476.1.0 - 6.1.266.2.0 - 6.2.17 +1 more | Medium |
AIKIDO-2026-10572 spring-webflux is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 5.3.0 - 5.3.47, 6.1.0 - 6.1.26, 6.2.0 - 6.2.17 and 7.0.0 - 7.0.6. | 5.3.0 - 5.3.476.1.0 - 6.1.266.2.0 - 6.2.17 +1 more | Low |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework:spring-beans Version 7.0.8 | — | — |
org.springframework:spring-core Version 7.0.8 | — | — |
org.springframework:spring-web Version 7.0.8 | — | — |
io.projectreactor:reactor-core Version 3.8.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant