---
cve: "CVE-2026-47873"
severity: "HIGH"
cvss: 8.0
epss: "18%"
vendor: "Spring"
kev: false
exploited: false
published: "2026-07-30 06:25:52"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T20:08:05+02:00"
---

# CVE-2026-47873

> 8.0 HIGH

## Beschreibung

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier

## CVSS-Vektor

```
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://spring.io/security/cve-2026-47873>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-47873) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
