Skip to content
VMwareCVE-2026-47882

When enabling Spring Boot DevTools support for a remote application target

High8.3CVE-2026-47882 · Published Jul 30, 2026 · updated Aug 1, 2026

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

VMware advisory

Affected versions

PackageAffectedFixed in
Spring Tools for Eclipse
Product
<= 5.2.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-338

More VMware advisories

All VMware
Advisory
VMware ESX contains an insufficient logging vulnerability
Low2.7Jul 30
VMware Cloud Foundation: authentication bypass
Critical9.8Jul 30
VMware Cloud Foundation: path traversal
Critical9.8Jul 30
VMware Cloud Foundation: out-of-bounds write
Critical9.3Jul 30
VMware Cloud Foundation: out-of-bounds read
High7.6Jul 30
VMware Spring Tools for: secrets in logs
Low3.3Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.