← Vulnerability feed

Vulnerability record · CVE-2018-1257 · published 11 May 2018

CVE-2018-1257: Vmware spring framework vulnerability

Vmware · Spring Framework

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

6.5 CVSS 3.1 Medium EPSS 3.1% · top 12.7%
6.5CVSS 3.1 base score, v2 4.0
3.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
30Affected product versions listed by NVD
22References
17 Jun 2026Last modified by NVD

Description

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

30 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html PatchThird Party Advisory
http://www.securityfocus.com/bid/104260 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2018:1809 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3768 Third Party Advisory
https://pivotal.io/security/cve-2018-1257 Vendor Advisory
https://www.oracle.com/security-alerts/cpujan2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html PatchThird Party Advisory
http://www.securityfocus.com/bid/104260 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2018:1809 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3768 Third Party Advisory
https://pivotal.io/security/cve-2018-1257 Vendor Advisory
https://www.oracle.com/security-alerts/cpujan2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html PatchThird Party Advisory

Track CVE-2018-1257 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2020-2555Oracle Coherence T3 deserialization allows unauthenticated remote code executionOracle Coherence (Fusion Middleware) deserializes untrusted data reachable over the T3 protocol, allowing an unauthenticated network attacker to exec…KEVEPSS 97%analysed9.8CVE-2019-2725Oracle WebLogic Server Web Services deserialization RCEOracle WebLogic Server's Web Services subcomponent contains an injection flaw (CWE-74) that allows unauthenticated remote code execution over HTTP. I…KEVEPSS 100%analysed9.8CVE-2017-9841PHPUnit eval-stdin.php remote PHP code executionPHPUnit before 4.8.28 and 5.x before 5.6.3 ships Util/PHP/eval-stdin.php, which evaluates HTTP POST body content as PHP when it begins with a "<?php …KEVEPSS 100%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed8.8CVE-2024-20953Oracle Agile PLM Export deserialization allows takeoverOracle Agile Product Lifecycle Management 9.3.6 contains a deserialization flaw in the Export component. A low-privileged attacker with network acces…KEVEPSS 3.9%analysed8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed7.5CVE-2024-21287Oracle Agile PLM Framework incorrect authorization exposes dataOracle Agile PLM Framework 9.3.6 contains an incorrect authorization flaw in the Software Development Kit / Process Extension component. An unauthent…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2018-1257), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.