91 Security Flaws Fixed in Spring, the Java Framework Powering Hundreds of Thousands of Apps

One critical flaw lets attackers silently alter user records. Over 200 vulnerabilities have already been patched in Spring this year, a sharp rise tied to Broadcom's push into AI.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A Java development environment showing Spring framework code with multiple security vulnerability indicators and patch notifications stacked in the interface
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Broadcom released patches fixing 91 vulnerabilities in its Spring Java framework during the last week of June 2025.
  • One flaw, CVE-2026-59270, is rated critical and lets an attacker log in and alter user records in Spring Security's built-in directory system.
  • Cybersecurity firm Sonatype found the patches touch more than 200,000 software components used across the industry.
  • Spring has patched more than 200 vulnerabilities so far in 2025, up from 16 in all of 2024.
  • Several older Spring flaws are listed by CISA as actively exploited in the real world.

What is Spring, and why should you care?

Spring is a free, open-source toolkit that developers use to build business applications: payroll systems, booking platforms, banking portals, and similar services. It runs on Java and is one of the most widely deployed frameworks around.

Broadcom, which now maintains Spring after its VMware acquisition, pushed out the fixes last week, as first reported by SecurityWeek.

How bad is the worst flaw?

The single critical-rated vulnerability is CVE-2026-59270. It lives inside Spring Security's embedded UnboundID LDAP server, an internal directory used to store and look up user credentials. An attacker who hits this flaw can authenticate without proper authorisation and quietly edit entries in that directory, changing account details or access rights without leaving obvious traces.

Sonatype separately flagged CVE-2026-59285 as a critical remote code execution flaw in Spring for GraphQL. Remote code execution means an attacker can run their own commands on a server from anywhere on the internet, no physical access needed.

CVE Component Severity Impact
CVE-2026-59270 Spring Security LDAP Critical Unauthorised login and record modification
CVE-2026-59285 Spring for GraphQL Critical Remote code execution
CVE-2026-59318 Spring AI tool-calling Medium Privilege escalation via prompt injection
Multiple others Spring Security, Reactor, AMQP, Batch High XSS, data leaks, denial of service, security bypasses

XSS, or cross-site scripting, is an attack where criminals inject malicious code into a web page that then runs inside a victim's browser. Denial of service means crashing a system so it stops responding to legitimate users.

Why is the number of Spring flaws rising so fast?

The numbers are stark. Spring has patched more than 200 vulnerabilities already in 2025, compared to 16 the previous year. Sonatype attributes the surge directly to Broadcom expanding Spring's AI-related features: more new code means more places for flaws to hide. It's the same dynamic we flagged on 14 August in our piece on security teams' shrinking capacity to absorb this kind of volume.

These aren't theoretical risks. CISA's Known Exploited Vulnerabilities catalogue includes several Spring flaws used in real attacks, among them Spring4Shell, a 2022 vulnerability that saw widespread exploitation.

What should developers do right now?

If your organisation builds or maintains software using any Spring component, check whether your version is affected and apply Broadcom's patches as quickly as your testing cycle allows. Sonatype's analysis found more than 200,000 software components are touched by these updates, so exposure is broad.

End users don't need to act directly. Watch for security notices from the apps and platforms you rely on and update promptly when asked.

Should you worry if you're not a developer?

Probably not today, but the scale here matters. A framework this widely used, patching at this pace, with CISA-confirmed exploitation of older flaws in the same family, means the risk lands on services many people use without knowing Spring is underneath them.

© 2026 Threat Vectr