Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2016-1000027: Spring Web component can let attackers run code on server

CVE-2016-1000027 · published 3 days ago
Summary

The Spring Web library used in Java applications (including versions supplied by Spring Framework, VMware, Root, and Debian) has a weakness that could let an attacker run their own code on your server. This could lead to unauthorized access, data loss, or further attacks on your network. Apply the latest updates from your software provider or package manager as soon as possible to close the risk.

What to do
  • Update springframework org.springframework:spring-web to version 6.0.0.
  • Update root io.root.org.springframework:spring-web to version 5.3.23-root.io.2.
  • Update root io.root.org.springframework:spring-web to version 5.3.23-root.io.3.
  • Update springframework org.springframework:spring-web to version 5.3.23-aikido.3.
  • Update root io.root.org.springframework:spring-web to version 5.3.23-root.io.4.
  • Update springframework org.springframework:spring-web to version 5.3.23-aikido.4.
  • Update springframework org.springframework:spring-web to version 5.3.23-aikido.6.
  • Update root io.root.org.springframework:spring-web to version 5.3.23-root.io.6.
  • Update debian libspring-java to version 4.2.7-1.
  • Update org.springframework:spring-web to version 5.3.23-aikido.6.
  • Update io.root.org.springframework:spring-web to version 5.3.23-root.io.6.
  • Update vmware spring_framework to version 6.0.0 or later.
Affected software
Ecosystem VendorProductAffected versions
maven springframework org.springframework:spring-web < 6.0.0
Fix: upgrade to 6.0.0
– vmware spring_framework < 6.0.0
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
Root:Maven root io.root.org.springframework:spring-web < 5.3.23-root.io.2
< 5.3.23-root.io.3
< 5.3.23-root.io.4
< 5.3.23-root.io.6
Fix: upgrade to 5.3.23-root.io.2
Root:Maven springframework org.springframework:spring-web < 5.3.23-aikido.3
< 5.3.23-aikido.4
< 5.3.23-aikido.6
Fix: upgrade to 5.3.23-aikido.3
Debian:12 debian libspring-java < 4.2.7-1
Fix: upgrade to 4.2.7-1
Debian:13 debian libspring-java < 4.2.7-1
Fix: upgrade to 4.2.7-1
Debian:14 debian libspring-java < 4.2.7-1
Fix: upgrade to 4.2.7-1
Root:Maven – org.springframework:spring-web < 5.3.23-aikido.6
Fix: upgrade to 5.3.23-aikido.6
Root:Maven – io.root.org.springframework:spring-web < 5.3.23-root.io.6
Fix: upgrade to 5.3.23-root.io.6
Original advisory text
CVE-2016-1000027 in org.springframework:spring-web - Patched by Root
Root has patched CVE-2016-1000027 in the org.springframework:spring-web package for Root:Maven. Multiple fixed versions available.
Severity
9.8 Critical
CVSS 3.1: 9.8 (GHSA)
Exploitation
EPSS 33%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published24 Sep 2026
Updated24 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta