Spring security advisory (AV26-759)
Serial number: AV26-759 Date: July 30, 2026 As of July 30, 2026, Spring is affected by vulnerabilities in the following products: Spring Tools for Eclipse Prior to or equal to 5.2.0 Spring Tools for VSCode / Cursor / Theia Prior to or equal to 2.2.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-47858: live information startup mode is vulnerable for remote code execution CVE-2026-47873: Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces CVE-2026-47882: Spring Boot DevTools remote secret generated with a non-cryptographic PRNG CVE-2026-59326: HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server CVE-2026-59327: Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations CVE-2026-59328: Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips Spring | Security Advisories
CSIRTS triage
- What
- Multiple vulnerabilities exist, including one that allows for remote code execution.
- Who is affected
- Users of Spring Tools for Eclipse and Spring Tools for VSCode / Cursor / Theia prior to the specified versions are affected.
- Urgency
- Remediation is necessary, but the vulnerabilities are not actively exploited.
- Action
- Users should review and apply updates as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Spring Tools for Eclipse, Spring Tools for VSCode / Cursor / Theia
Get an email when a new Spring Tools for Eclipse, Spring Tools for VSCode / Cursor / Theia advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-759
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-478580.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all scored CVEs.
- Low exploitation riskCVE-2026-478730.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2026-478820.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-593260.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-593270.08% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all scored CVEs.
- Low exploitation riskCVE-2026-593280.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-47858 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47873 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47882 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59326 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59327 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59328 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-59328: Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native em…nvd
- mediumCVE-2026-59327: Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote…nvd
- lowCVE-2026-59326: The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/H…nvd
- highCVE-2026-47882: When enabling Spring Boot DevTools support for a remote application target (for example a Dock…nvd
- highCVE-2026-47873: The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all…nvd
- highCVE-2026-47858: Starting Spring Boot applications in the Spring Tools with the live information mode enabled m…nvd
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30