Serial number: AV26-759
Date: July 30, 2026
As of July 30, 2026, Spring is affected by vulnerabilities in the following products:
- Spring Tools for Eclipse
- Prior to or equal to 5.2.0
- Spring Tools for VSCode / Cursor / Theia
- Prior to or equal to 2.2.0
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- CVE-2026-47858: live information startup mode is vulnerable for remote code execution
- CVE-2026-47873: Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces
- CVE-2026-47882: Spring Boot DevTools remote secret generated with a non-cryptographic PRNG
- CVE-2026-59326: HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server
- CVE-2026-59327: Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations
- CVE-2026-59328: Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips
- Spring | Security Advisories