nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-47873 CVE-2026-47873
HIGH
Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces
Record summary
CVE-2026-47873 has a selected CVSS score of 8.0 (high).
Description
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Spring Tools for EclipseBrowse Spring / Spring Tools for EclipseDefault status: unaffected | CVE List | Through 5.2.0 | affected |
References
2spring.io
https://spring.io/security/cve-2026-47873