IndexedVerified
Java/Spring Security
Spring and JVM web SAST rules aggregated across verified providers.
Fetch pack
greprules pack fetch java-spring-security --engine opengrepcurl https://api.greprules.io/api/packs/java-spring-security.tar.gz -o java-spring-security.tar.gzIncluded rules
CVE-2026-73244: Java Path Traversal Directory Stream
cve-2026-73244-java-path-traversal-directory-streamCVE-2026-66300: Spring Reflected Xss Exception Responseentitycve-2026-66300-spring-reflected-xss-exception-responseentityCVE-2026-59287: Flux Interval Unmanaged Subscriptioncve-2026-59287-flux-interval-unmanaged-subscriptionCVE-2026-59285: Jackson Polymorphic Type Validator Allow Map Basetypecve-2026-59285-jackson-polymorphic-type-validator-allow-map-basetypeCVE-2026-47875: Jackson Untrusted Class Deserializationcve-2026-47875-jackson-untrusted-class-deserializationCVE-2026-47860: Spring Amqp Unbounded Decompressioncve-2026-47860-spring-amqp-unbounded-decompressionCVE-2026-41901: Thymeleaf Cve 2026 41901 Typename Firstchar Shortcutcve-2026-41901-thymeleaf-cve-2026-41901-typename-firstchar-shortcutCVE-2026-40477: Thymeleaf Ssti Incomplete Expression Recognizercve-2026-40477-thymeleaf-ssti-incomplete-expression-recognizerCVE-2026-32613: Java Spel Standard Evaluation Context Rcecve-2026-32613-java-spel-standard-evaluation-context-rceCVE-2026-8738: Publiccms Trade Payment Idor Missing Session Usercve-2026-8738-publiccms-trade-payment-idor-missing-session-userCVE-2026-3789: Ssrf Resttemplate Unvalidated Dto Urlcve-2026-3789-ssrf-resttemplate-unvalidated-dto-urlCVE-2025-58748: Dataease Jdbc Url Scheme Not Validatedcve-2025-58748-dataease-jdbc-url-scheme-not-validatedCVE-2025-28401: Shiro Missing Csrf Protectioncve-2025-28401-shiro-missing-csrf-protectionCVE-2025-7906: Shiro Missing Csrf Protectioncve-2025-7906-shiro-missing-csrf-protectionCVE-2024-57155: Spring Handler Interceptor Auth Bypass Returns True On Null Usercve-2024-57155-spring-handler-interceptor-auth-bypass-returns-true-on-null-userAll included rules loaded.