Skip to content
VMwareCVE-2026-59328

VMware Spring Tools for Eclipse: spoofing

Medium4.2CVE-2026-59328 · Published Jul 30, 2026

Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

VMware advisory

Affected versions

PackageAffectedFixed in
Spring Tools for Eclipse
Product
<= 5.2.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-79

More VMware advisories

All VMware
Advisory
VMware ESX contains an insufficient logging vulnerability
Low2.7Jul 30
VMware Cloud Foundation: authentication bypass
Critical9.8Jul 30
VMware Cloud Foundation: path traversal
Critical9.8Jul 30
VMware Cloud Foundation: out-of-bounds write
Critical9.3Jul 30
VMware Cloud Foundation: out-of-bounds read
High7.6Jul 30
VMware Spring Tools for: secrets in logs
Low3.3Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.