CVE-2026-40998: Jaxp13 XPath XXE via StreamSource and SAXSource

HIGH | JUNE 10, 2026 | CVE-2026-40998
Description Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK’s default DocumentBuilderFactory behavior instead of Spring’s hardened parser configuration…

CVE-2026-41699: Unsafe Deserialization in Spring GraphQL

HIGH | JUNE 10, 2026 | CVE-2026-41699
Description Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. More precisely, an application is vulnerable when all the following are true: the application is using Spring GraphQL the…

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all