CVE-2026-47873
Received
Received - Intake
Spring Tools for Eclipse Container Port Exposure
Vulnerability report for CVE-2026-47873, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-30
Last updated on: 2026-07-30
Assigner: VMware
Description
Description
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| vmware | spring_tools_for_eclipse | to 5.2.0 (exc) |
| spring | tools_for_eclipse | to 5.3.0 (exc) |
| spring | tools_for_eclipse | to 5.2.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |