91 Vulnerabilities Patched in Spring Application Framework

91 Vulnerabilities Patched in Spring Application Framework
Broadcom’s Spring framework received patches for 91 vulnerabilities, including a critical flaw in Spring Security’s embedded UnboundID LDAP server and other issues affecting widely used Spring projects. Sonatype noted that the fixes span more than 200,000 software components, with two standout bugs in Spring for GraphQL and Spring AI drawing particular concern. #Spring #Broadcom #SpringSecurity #SpringAI #SpringforGraphQL #CISA #Spring4Shell

Keypoints

  • Broadcom released patches for 91 vulnerabilities in Spring.
  • CVE-2026-59270 is a critical flaw in Spring Security’s embedded UnboundID LDAP server.
  • More than a dozen issues are rated high severity, including RCE and XSS risks.
  • Sonatype says the fixes affect over 200,000 software components across multiple Spring projects.
  • CVE-2026-59285 and CVE-2026-59318 were highlighted as especially important security issues.

Read More: https://www.securityweek.com/91-vulnerabilities-patched-in-spring-application-framework/