Spring WebSocket
100%
Total Score
99
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11162 spring-websocket is vulnerable to Predictable Session IDs in versions 5.3.0 - 5.3.48, 6.1.0 - 6.1.27, 6.2.0 - 6.2.18 and 7.0.0 - 7.0.7. | 5.3.0 - 5.3.486.1.0 - 6.1.276.2.0 - 6.2.18 +1 more | Medium |
CVE-2025-41254 org.springframework:spring-websocket is vulnerable to Cross-Site Request Forgery (CSRF) in versions 6.2.0 - 6.2.12, 6.1.0 - 6.1.21, 6.0.0 - 6.0.23 and 0.0.0 - 5.3.39. | 0.0.0 - 5.3.396.0.0 - 6.0.236.1.0 - 6.1.21 +1 more | Medium |
AIKIDO-2024-10362 spring-websocket is vulnerable to Improper Handling of Case Sensitivity in versions 0.0.1 - 5.3.40, 6.0.0 - 6.0.24 and 6.1.0 - 6.1.13. | 0.0.1 - 5.3.406.0.0 - 6.0.246.1.0 - 6.1.13 | Low |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework:spring-context Version 7.0.8 | — | — |
org.springframework:spring-core Version 7.0.8 | — | — |
org.springframework:spring-web Version 7.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant