Every CVE whose affected-product data names Broadcom Spring Batch, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (5)
CVE-2019-3774 — CVSS 9.8 (critical): Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when…
CVE-2020-5411 — CVSS 8.1 (high): When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution…
CVE-2026-47881 — CVSS 5.9 (medium): Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for example, a CSV field…
CVE-2026-47875 — CVSS 5.6 (medium): Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack…
CVE-2026-47878 — CVSS 5.6 (medium): DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to…