Sonatype tracked 91 Spring CVEs affecting an estimated 209,569 software components in the August 20, 2026 disclosure.
A critical unsafe deserialization vulnerability in Spring for GraphQL, tracked as CVE-2026-59285, could enable remote code ...