Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > 91 Vulnerabilities Patched in Spring Application Framework

91 Vulnerabilities Patched in Spring Application Framework

Broadcom’s spring updates patch 91 vulnerabilities across major components.

Broadcom released Spring framework updates fixing 91 flaws, including a critical issue in Spring Security’s embedded LDAP server that could let attackers authenticate and alter directory entries. More than a dozen high‑severity bugs enable XSS, information disclosure, RCE, DoS and security bypasses, with additional medium and low‑severity issues affecting over 200,000 components across projects such as Spring Security, Spring AI, Cloud Config and Reactor. Sonatype highlighted a critical GraphQL RCE and a Spring AI prompt‑injection escalation risk as part of a surge driven by Broadcom’s AI‑assisted development, with more than 200 Spring vulnerabilities patched this year. Open‑source maintainers are urged to review and apply the latest fixes given past exploitation of Spring flaws like Spring4Shell.

Read more:

https://www.securityweek.com/91-vulnerabilities-patched-in-spring-application-framework/