logo

91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain

ID: 768b9b27-46fc-522a-8eeb-b408a1ab4c0d

STIX ID: report--768b9b27-46fc-522a-8eeb-b408a1ab4c0d

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Divya

...
...

Broadcom disclosed 91 CVEs across Spring projects (Spring Security, Spring Cloud, Spring GraphQL, Spring AI, Reactor, and more), including a critical CVE-2026-59285 (unsafe deserialization, CVSS 9.2); Sonatype estimates approximately 209,569 impacted software components, underscoring widespread supply-chain exposure and remediation challenges—organizations are advised to inventory affected versions, prioritize internet-facing services and GraphQL/AI-exposed apps, and apply upgrades while validating compatibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.