CVE-2026-59328

Source
https://cve.org/CVERecord?id=CVE-2026-59328
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59328.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-59328
Published
2026-07-30T05:29:20Z
Modified
2026-10-02T03:47:29Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips
Details

Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

Database specific
{
    "cna_assigner": "vmware",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59328.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "5.2.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/spring-projects/spring-tools

Affected ranges

Type
GIT
Repo
https://github.com/spring-projects/spring-tools
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:broadcom:spring_tools:*:*:*:*:*:eclipse:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.3.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

3.*
3.9.15.RELEASE
3.9.7.RELEASE
4.*
4.0.0.RELEASE
4.0.1.RELEASE
4.0.2.RELEASE
4.1.1.RELEASE
4.1.2.RELEASE
4.10.0.RELEASE
4.11.0.RELEASE
4.11.1.RELEASE
4.12.0.RELEASE
4.12.1.RELEASE
4.13.0.RELEASE
4.13.1.RELEASE
4.14.0.RELEASE
4.14.1.RELEASE
4.15.0.RELEASE
4.15.2.RELEASE
4.15.3.RELEASE
4.16.0.RELEASE
4.16.1.RELEASE
4.17.0.RELEASE
4.17.1.RELEASE
4.17.2.RELEASE
4.18.0.RELEASE
4.18.1.RELEASE
4.19.0.RELEASE
4.2.0.RELEASE
4.2.1.RELEASE
4.2.2.RELEASE
4.20.0.RELEASE
4.20.1.RELEASE
4.21.0.RELEASE
4.21.1.RELEASE
4.22.0.RELEASE
4.22.1.RELEASE
4.23.0.RELEASE
4.24.0.RELEASE
4.25.0.RELEASE
4.26.0.RELEASE
4.27.0.RELEASE
4.28.0.RELEASE
4.29.0.RELEASE
4.3.0.RELEASE
4.3.1.RELEASE
4.3.2.RELEASE
4.30.0.RELEASE
4.31.0.RELEASE
4.4.1.RELEASE
4.4.2.RELEASE
4.5.0.RELEASE
4.5.1.RELEASE
4.6.0.RELEASE
4.6.1.RELEASE
4.6.2.RELEASE
4.7.0.RELEASE
4.7.1.RELEASE
4.7.2.RELEASE
4.8.0.RELEASE
4.8.1.RELEASE
4.9.0.RELEASE
5.*
5.0.0.RC1
5.0.0.RC2
5.0.0.RELEASE
5.1.0.RELEASE
5.2.0.RELEASE
CF-Manifest-LS-STS-3.*
CF-Manifest-LS-STS-3.9.0.RELEASE
Other
REPO-REORG
REPO-REORG-2020
V_0.*
V_0.0.4-RC.1
V_0.0.5
V_0.0.5-RC.1
V_0.0.5-RC.2
V_0.0.5-RC.3
V_0.0.5-RC.4
V_0.0.5-RC.5
V_0.0.5-RC.6
V_0.0.5-RC.7
V_0.0.6
V_0.0.6-RC.1
V_0.0.7
V_0.0.7-RC.1
V_0.0.8
V_0.0.8-RC.1
V_0.0.9
V_0.0.9-RC.2
V_0.0.9-RC.3
V_0.0.9-RC.4
V_0.1.0
V_0.1.0-RC.1
V_0.1.2
V_0.1.2-RC.1
V_0.1.2-RC.2
V_0.1.2-RC.3
V_0.1.3
V_0.1.3-RC.1
V_0.1.4
V_0.1.4-RC.1
V_0.2.1
V_0.2.1-RC.1
V_0.3.0
V_0.3.0-RC.1
V_0.3.1
V_0.3.1-RC.1
V_0.3.2-RC.1
V_0.4.0
V_0.4.0-RC.1
V_0.5.0
V_0.5.0-RC.1
V_0.5.0-RC.2
V_0.5.0-RC.3
V_0.6.0
V_0.6.0-RC.1
V_0.6.0-RC.2
V_0.6.0-RC.3
V_0.7.0-RC.1
V_1.*
V_1.0.0
V_1.0.0-RC.1
V_1.0.0-RC.2
V_1.0.0-RC.3
V_1.0.0-RC.4
V_1.0.0-RC.5
V_1.0.0-RC.6
V_1.1.0
V_1.1.0-RC.1
V_1.1.0-RC.3
V_1.1.0-RC.4
V_1.1.1
V_1.1.1-RC.1
V_1.1.1-RC.2
V_1.1.1-RC.3
V_1.10.0
V_1.10.0-RC.1
V_1.12.0
V_1.12.0-RC.1
V_1.12.0-RC.2
V_1.12.0-RC.3
V_1.12.0-RC.4
V_1.13.0
V_1.13.0-RC.1
V_1.14.0
V_1.14.0-RC.1
V_1.15.0
V_1.15.0-RC.1
V_1.16.0-RC.1
V_1.16.0-RC.2
V_1.17.0
V_1.17.0-RC.1
V_1.18.0
V_1.18.0-RC.1
V_1.2.0
V_1.2.0-RC.1
V_1.20.0
V_1.20.0-RC.1
V_1.21.0
V_1.21.0-RC.1
V_1.21.0-RC.2
V_1.22.0
V_1.22.0-RC.1
V_1.23.0
V_1.23.0-RC.1
V_1.23.0-RC.2
V_1.24.0
V_1.24.0-RC.1
V_1.25.0
V_1.25.0-RC.1
V_1.25.0-RC.2
V_1.25.1
V_1.25.1-RC.1
V_1.25.1-RC.2
V_1.26.0-RC.2
V_1.27.0
V_1.27.0-RC.1
V_1.28.0
V_1.28.0-RC.1
V_1.29.0
V_1.29.0-RC.1
V_1.29.0-RC.2
V_1.3.0
V_1.3.0-RC.1
V_1.30.0
V_1.30.0-RC.1
V_1.31.0
V_1.31.0-RC.1
V_1.31.0-RC.2
V_1.32.0
V_1.32.0-RC.1
V_1.32.0-RC.2
V_1.33.0
V_1.33.0-RC.2
V_1.34.0
V_1.34.0-RC.1
V_1.35.0
V_1.35.0-RC.1
V_1.36.0-RC.1
V_1.37.0
V_1.37.0-RC.1
V_1.37.0-RC.2
V_1.38.0
V_1.38.0-RC.1
V_1.38.0-RC.3
V_1.39.0
V_1.39.0-RC.1
V_1.4.0
V_1.4.0-RC.1
V_1.40.0
V_1.40.0-RC.1
V_1.41.0
V_1.41.0-RC.1
V_1.41.0-RC.2
V_1.42.0
V_1.42.0-RC.1
V_1.42.0-RC.2
V_1.42.0-RC.3
V_1.42.0-RC.4
V_1.43.0
V_1.43.0-RC.1
V_1.44.0
V_1.44.0-RC.1
V_1.44.0-RC.2
V_1.45.0
V_1.45.0-RC.1
V_1.45.0-RC.2
V_1.45.0-RC.3
V_1.46.0-RC.1
V_1.46.0-RC.2
V_1.47.0
V_1.47.0-RC.1
V_1.49.0
V_1.49.0-RC.1
V_1.49.0-RC.2
V_1.5.0
V_1.5.0-RC.1
V_1.5.0-RC.2
V_1.5.0-RC.3
V_1.50.0
V_1.50.0-RC.1
V_1.50.0-RC.2
V_1.51.0
V_1.51.0-RC.1
V_1.51.0-RC.2
V_1.51.0-RC.3
V_1.52.0
V_1.52.0-RC.1
V_1.53.0
V_1.53.0-RC.1
V_1.53.0-RC.2
V_1.53.0-RC.3
V_1.54.0
V_1.54.0-RC.1
V_1.54.0-RC.2
V_1.55.0
V_1.55.0-RC.1
V_1.6.0
V_1.6.0-RC.1
V_1.7.0
V_1.7.0-RC.1
V_1.7.0-RC.2
V_1.8.0
V_1.8.0-RC.1
V_1.9.0
V_1.9.0-RC.1
V_1.9.0-RC.2
v0.*
v0.0.1
v2.*
v2.2.0
vscode-boot-dev-pack-0.*
vscode-boot-dev-pack-0.2.2
vscode-bosh-1.*
vscode-bosh-1.56.0-M1
vscode-concourse-0.*
vscode-concourse-0.0.1-RELEASE
vscode-concourse-1.*
vscode-concourse-1.56.0-RC1
vscode-manifest-yaml-0.*
vscode-manifest-yaml-0.0.1-RC1
vscode-manifest-yaml-0.0.1-RELEASE
vscode-manifest-yaml-0.0.2-RC1
vscode-manifest-yaml-0.0.2-RELEASE
vscode-spring-boot-1.*
vscode-spring-boot-1.56.0-RC1
vscode-spring-boot-1.56.0-RC2
vscode-spring-boot-1.57.0-RC1
vscode-spring-boot-1.57.0-RC2
vscode-spring-boot-1.57.0-RC3
vscode-spring-boot-1.58.0-RC1
vscode-spring-boot-1.59.0-RC1
vscode-spring-boot-1.59.0-RC2
vscode-spring-boot-1.60.0-RC1
vscode-spring-boot-1.60.0-RC2
vscode-spring-boot-1.61.0-RC1
vscode-spring-boot-1.61.0-RC2
vscode-spring-boot-1.62.0-RC1
vscode-spring-boot-1.63.0-RC1
vscode-spring-boot-1.63.0-RC2
vscode-spring-boot-2.*
vscode-spring-boot-2.0.0-RC2
vscode-spring-boot-2.0.0-RC3
vscode-spring-boot-2.1.0-RC1
vscode-spring-boot-2.1.0-RC2
vscode-spring-boot-2.1.0-RC3
vscode-spring-boot-2.2.0-RC1
vscode-spring-boot-2.3.0-RC1
vscode-spring-cli-0.*
vscode-spring-cli-0.9.0-RC1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59328.json"