org.springframework:spring-core

mavenv7.0.0-M6

Spring Core

License Apache-2.0permissive311 versions0 deps
spring-projects/spring-framework
35
/ 100
Health
update required

org.springframework:[email protected] has vulnerabilities — update to latest

Update to >= 2.5.7.SR023 to fix known vulnerabilities

  • Low health score (35/100)
  • 8 high severity vulnerabilities
Health breakdown0 – 100
10/25
maintenance
0/20
popularity
0/25
security
15/15
maturity
10/15
community
Vulnerabilities
18
8 high10 medium
Advisories (18)
SeverityIDSummaryFixed in
highCVE-2018-1272Possible privilege escalation in org.springframework:spring-core5.0.5
mediumCVE-2015-0201Moderate severity vulnerability that affects org.springframework:spring-core4.1.5
mediumCVE-2021-22060Log entry injection in Spring Framework5.2.19
highCVE-2016-5007Spring Security and Spring Framework may not recognize certain paths that should be protected4.1.1
highCVE-2018-1258Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass5.0.6.RELEASE
mediumCVE-2018-11040Moderate severity vulnerability that affects org.springframework:spring-core4.3.18.RELEASE
mediumCVE-2011-2894Spring Framework and Spring Security vulnerable to Deserialization of Untrusted Data2.0.7
highCVE-2018-15756Denial of Service in Spring Framework4.3.20.RELEASE
mediumCVE-2018-1271Path Traversal in org.springframework:spring-core4.3.15
highCVE-2025-41249Spring Framework annotation detection mechanism may result in improper authorization6.2.11
highCVE-2015-5211Files or Directories Accessible to External Parties in org.springframework:spring-core3.2.15
highCVE-2024-22233Spring Framework server Web DoS Vulnerability6.0.16
mediumCVE-2018-1257Denial of Service in org.springframework:spring-core4.3.17
mediumCVE-2021-22096Improper Output Neutralization for Logs in Spring Framework5.3.11
mediumCVE-2014-3578Improper Limitation of a Pathname to a Restricted Directory in Spring Framework4.0.5
mediumCVE-2018-1199Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core4.1.5
mediumCVE-2009-1190Spring Framework Inefficient Regular Expression Complexity3.0.0.RELEASE
highCVE-2011-2730Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework2.5.7.SR023
Threat intelligence
1 likely exploited (EPSS ≥ 0.5)
Threat tier per vulnerability derived from CISA KEV catalog + FIRST.org EPSS scores.
OSS Scorecard
OpenSSF security posture score
5.7/10
moderate
Maintainer trust
Active maintainers (3m)
16
Contributors (12m)
16
Primary author dominance
60%
GitHub stars
59,858

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/maven/org.springframework:spring-core

Last updated · 2025-06-12T10:14:17+00:00