Every CVE whose affected-product data names Broadcom Spring Tools, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (6)
CVE-2026-47882 — CVSS 8.3 (high): When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the…
CVE-2026-47858 — CVSS 8.0 (high): Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable…
CVE-2026-47873 — CVSS 8.0 (high): The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0)…
CVE-2026-59327 — CVSS 4.4 (medium): Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the…
CVE-2026-59328 — CVSS 4.2 (medium): Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript…
CVE-2026-59326 — CVSS 3.3 (low): The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level…