Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2635-1 | libspring-java security update |
EUVD |
EUVD-2018-0587 | Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests. |
Github GHSA |
GHSA-f26x-pr96-vw86 | Moderate severity vulnerability that affects org.springframework:spring-core |
Thu, 08 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2026-10-08T21:13:59.757Z
Reserved: 2018-05-14T00:00:00.000Z
Link: CVE-2018-11040
Updated: 2024-08-05T07:54:36.553Z
Status : Modified
Published: 2018-06-25T15:29:00.363
Modified: 2026-10-08T22:16:44.350
Link: CVE-2018-11040
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA