CVE-2026-47873: Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces
Published Jul 30, 2026
·Updated
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Affected Software
1 affected component
Spring Spring Tools for Eclipse<=5.2.0
Event History
Jul 30, 2026
CVE Published
via MITRE·05:23 AM
Data Sourced
via MITRE·05:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:25 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-47873?
The severity of CVE-2026-47873 is classified as high with a score of 8.
2
How do I fix CVE-2026-47873?
To fix CVE-2026-47873, update Spring Tools for Eclipse to version 5.2.1 or later.
3
What are the risks associated with CVE-2026-47873?
CVE-2026-47873 poses risks of unauthorized access and remote code execution due to unauthenticated debug and JMX ports being exposed.
4
Which versions of Spring Tools are affected by CVE-2026-47873?
Spring Tools for Eclipse version 5.2.0 and earlier are affected by CVE-2026-47873.
5
Is CVE-2026-47873 a local or remote vulnerability?
CVE-2026-47873 is a remote vulnerability as it can be exploited over the network due to exposed ports.