Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-59317

Publication date:
27/08/2026
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation.<br /> Spring for Apache Kafka 4.1.0<br /> Spring for Apache Kafka 4.0.0 - 4.0.6<br /> Spring for Apache Kafka 3.0.0 - 3.3.16<br /> Spring for Apache Kafka 2.9.0 - 2.9.14<br /> Spring for Apache Kafka 2.8.12 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59319

Publication date:
27/08/2026
RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values without applying RediSearchUtil.escape(), unlike get(), clear(), and findByTimeRange() in the same class which do escape their inputs. An application that passes user-controlled values to findByMetadata() on a tag-typed metadata field allows an attacker to inject RediSearch syntax (e.g. x} | *) that breaks out of the tag clause and matches all indexed chat messages across every conversation in the index.<br /> Spring AI 2.0.0
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59298

Publication date:
27/08/2026
Potential for improper filtering of HTTP headers in Spring Cloud Function.<br /> Spring Cloud Function 5.0.0 - 5.0.3<br /> Spring Cloud Function 4.3.0 - 4.3.4<br /> Spring Cloud Function 4.2.0 - 4.2.7<br /> Spring Cloud Function 3.2.16 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59299

Publication date:
27/08/2026
Composition lookup can potentially poison base function in Spring Cloud Function.<br /> Spring Cloud Function 5.0.0 - 5.0.3<br /> Spring Cloud Function 4.3.0 - 4.3.4<br /> Spring Cloud Function 4.2.0 - 4.2.7<br /> Spring Cloud Function 3.2.16 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59300

Publication date:
27/08/2026
Potential for logging sensitive data in Spring Cloud Function AWS.<br /> Spring Cloud Function 5.0.0 - 5.0.3<br /> Spring Cloud Function 4.3.0 - 4.3.4<br /> Spring Cloud Function 4.2.0 - 4.2.7<br /> Spring Cloud Function 3.2.16 and earlier
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59301

Publication date:
27/08/2026
Potential for logging sensitive data in Spring Cloud Function Azure.<br /> Spring Cloud Function 5.0.0 - 5.0.3<br /> Spring Cloud Function 4.3.0 - 4.3.4<br /> Spring Cloud Function 4.2.0 - 4.2.7
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59302

Publication date:
27/08/2026
Potential for logging sensitive data in Spring Cloud Stream.<br /> Spring Cloud Stream 5.0.0 - 5.0.2<br /> Spring Cloud Stream 4.3.0 - 4.3.3<br /> Spring Cloud Stream 4.2.0 - 4.2.6
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59303

Publication date:
27/08/2026
Dynamic destination cache size is not properly bound in Spring Cloud Stream.<br /> Spring Cloud Stream 5.0.0 - 5.0.2<br /> Spring Cloud Stream 4.3.0 - 4.3.3<br /> Spring Cloud Stream 4.2.0 - 4.2.6
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59304

Publication date:
27/08/2026
Improper caching of the original content type in Spring Cloud Stream Avro.<br /> Spring Cloud Stream 5.0.0 - 5.0.2<br /> Spring Cloud Stream 4.3.0 - 4.3.3<br /> Spring Cloud Stream 4.2.0 - 4.2.6
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59305

Publication date:
27/08/2026
Partition interceptor may be improperly added while sending message.<br /> Spring Cloud Stream 5.0.0 - 5.0.2<br /> Spring Cloud Stream 4.3.0 - 4.3.3<br /> Spring Cloud Stream 4.2.0 - 4.2.6
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59306

Publication date:
27/08/2026
Potential for deserialization of untrusted types in Spring Cloud Stream.<br /> Spring Cloud Stream 5.0.0 - 5.0.2<br /> Spring Cloud Stream 4.3.0 - 4.3.3<br /> Spring Cloud Stream 4.2.0 - 4.2.6
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026

CVE-2026-59288

Publication date:
27/08/2026
The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim&amp;#39;s browser might leak confidential information to the attacker&amp;#39;s website.<br /> Spring for GraphQL 2.0.0 - 2.0.4<br /> Spring for GraphQL 1.4.0 - 1.4.6<br /> Spring for GraphQL 1.1.0 - 1.3.9<br /> Spring for GraphQL 1.0.0 - 1.0.7
Severity CVSS v4.0: Pending analysis
Last modification:
27/08/2026