Spring patches 91 vulnerabilities, fixes critical LDAP flaw
Broadcom’s Spring issued updates last week that fix 91 vulnerabilities, including critical LDAP authentication flaw CVE-2026-59270 in Spring Security’s embedded UnboundID server.
Broadcom’s Spring development team released updates last week that address 91 security vulnerabilities. One issue, tracked as CVE-2026-59270, carries a critical rating and affects Spring Security’s embedded UnboundID LDAP server, where an attacker could authenticate and modify entries in the server’s in-memory directory.
The patch set includes more than a dozen high-severity fixes and a larger number of medium- and low-severity fixes. High-severity bugs impact multiple modules and can be exploited for cross-site scripting, information disclosure, remote code execution, denial-of-service, security bypasses and unauthorized access.
Security firm Sonatype reviewed the updates and reported they touch over 200,000 downstream software components. Affected Spring modules include Spring Security, Spring AI, Cloud Config, Data REST, Integration, Reactor Core, Reactor Netty, AMQP and Batch. Sonatype highlighted CVE-2026-59285, a remote code execution issue in Spring for GraphQL, and CVE-2026-59318, a medium-severity flaw in Spring AI’s tool-calling feature that could enable privilege escalation via prompt injection.
More than 200 Spring-related vulnerabilities have been patched so far this year, compared with 16 in 2025 and 22 in 2024. Some Spring vulnerabilities have been exploited in the wild in previous incidents, and several current issues are listed in the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog.
The Spring team and security analysts recommend that open source projects and enterprises using Spring components review the published patches and apply updates promptly. Spring is an open source framework for Java used to build enterprise applications, and Broadcom assumed responsibility for the project after acquiring VMware.








