How to audit a Spring Boot app in 2026
Is actuator/env open?
Deeper than a manual audit or a tool. At the scale AI agents attack.
The audit starts after signup. $49 for one month. Your report stays in your account.
- Actuator
- Heap dump
- Consoles and docs
- Known CVEs
01 / 08·running
Public surface
Other hosts and open ports
Signals
- Actuatorenv, mappings, configprops, and beans, with no login in front of them.
- Heap dumpA heap dump anyone on the internet can download.
- Consoles and docsJolokia, Swagger, OpenAPI, and the H2 console left on the app.
- Known CVEsPublished holes in the Spring Boot version the app reveals.
How the Spring Boot audit runs
What else is on this domain
Other hostnames on the same domain, then the ports those servers leave open, before anything Spring Boot-specific.
Subdomains
Staging, old admin hosts, and the other names on your domain.
Live hosts
Which of those names actually answer.
Open ports
What is listening, including the version when the server says it.
On your Spring Boot
Actuator endpoints, heap dumps, Swagger, the H2 console, and the Spring Boot version when it is visible.
Actuator
env, mappings, configprops, and beans, with no login in front of them.
Heap dump
A heap dump anyone on the internet can download.
Consoles and docs
Jolokia, Swagger, OpenAPI, and the H2 console left on the app.
Known CVEs
Published holes in the Spring Boot version the app reveals.
A report you can act on
Each issue names the host, shows the evidence, and says what to fix. Anything we could not confirm stays marked that way.
Evidence
The URL or file that proved it.
CVE ids
Only when we saw the version the advisory is about.
Account
The report opens after the $49 month is paid.
Questions about a Spring Boot audit
What the run covers, and when the report opens in the account.
Contact usAudit Spring Boot from the outside.
Deeper than a manual audit or a tool. At the scale AI agents attack.