CVE-2026-59328: Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips

Published Jul 30, 2026
·
Updated

Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

Affected Software

1 affected component
Pivotal Software Spring Tools for Eclipse<=5.2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Spring Tools for Eclipse to a version that resolves this vulnerability.

    Fixed in 5.2.0
  2. Compensating control

    Avoid using untrusted or compromised Initializr endpoints when creating Spring Boot starter projects in the New Spring Starter Project wizard (ensure Initializr endpoint is trusted).

Event History

Jul 30, 2026
CVE Published
via MITRE·05:29 AM
Data Sourced
via MITRE·05:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:25 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-59328?

CVE-2026-59328 has a medium severity score of 4.2.

2

How do I fix CVE-2026-59328?

To mitigate CVE-2026-59328, avoid using untrusted and compromised Initializr endpoints in the Spring Boot starter wizard.

3

What type of vulnerability is CVE-2026-59328?

CVE-2026-59328 is classified as a Cross-Site Scripting (XSS) vulnerability.

4

Which product is affected by CVE-2026-59328?

CVE-2026-59328 affects Pivotal Software Spring Tools for Eclipse.

5

What could be the impact of CVE-2026-59328?

The impact of CVE-2026-59328 could allow arbitrary script execution within the embedded browser of the tool.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203