CVE-2026-22735
published 2026-03-20CVE-2026-22735: Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0…
PriorityP411low2.6CVSS 3.1
AVNACHPRLUIRSUCNILAN
EPSS
0.11%
1.7th percentile
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| spring | spring_foundation | 5.3.0 – 5.3.46 | — |
| spring | spring_foundation | 6.1.0 – 6.1.25 | — |
| spring | spring_foundation | 6.2.0 – 6.2.16 | — |
| spring | spring_foundation | 7.0.0 – 7.0.5 | — |
| vmware | spring_framework | < 5.3.47 | 5.3.47 |
| vmware | spring_framework | >= 6.1.0 < 6.1.26 | 6.1.26 |
| vmware | spring_framework | >= 6.2.0 < 6.2.17 | 6.2.17 |
| vmware | spring_framework | >= 7.0.0 < 7.0.6 | 7.0.6 |
CVSS provenance
nvdv3.12.6LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Spring MVC and WebFlux has Server Sent Event stream corruption
osv·2026-03-20
CVE-2026-22735 [LOW] Spring MVC and WebFlux has Server Sent Event stream corruption
Spring MVC and WebFlux has Server Sent Event stream corruption
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
OSV
CVE-2026-22735: Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE)
osv·2026-03-20·CVSS 2.6
CVE-2026-22735 [LOW] CVE-2026-22735: Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE)
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
GHSA
Spring MVC and WebFlux has Server Sent Event stream corruption
ghsa·2026-03-20
CVE-2026-22735 [LOW] CWE-667 Spring MVC and WebFlux has Server Sent Event stream corruption
Spring MVC and WebFlux has Server Sent Event stream corruption
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Red Hat
org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring MVC and WebFlux: Stream corruption vulnerability when using Server-Sent Events
vendor_redhat·2026-03-19·CVSS 2.6
CVE-2026-22735 [LOW] CWE-115 org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring MVC and WebFlux: Stream corruption vulnerability when using Server-Sent Events
org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring MVC and WebFlux: Stream corruption vulnerability when using Server-Sent Events
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
A flaw was found in Spring MVC and WebFlux. A remote attacker with low privileges could exploit this vulnerability, requiring user interaction. This could lead to stream corruption, potentially affecting the integrity of data being transmitted.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security cri
Debian
CVE-2026-22735: libspring-java - Spring MVC and WebFlux applications are vulnerable to stream corruption when usi...
vendor_debian·2026·CVSS 2.6
CVE-2026-22735 [LOW] CVE-2026-22735: libspring-java - Spring MVC and WebFlux applications are vulnerable to stream corruption when usi...
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-22735 org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring MVC and WebFlux: Stream corruption vulnerability when using Server-Sent Events
bugzilla·2026-03-20·CVSS 2.6
CVE-2026-22735 [LOW] CVE-2026-22735 org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring MVC and WebFlux: Stream corruption vulnerability when using Server-Sent Events
CVE-2026-22735 org.springframework/spring-webmvc: org.springframework/spring-webflux: Spring MVC and WebFlux: Stream corruption vulnerability when using Server-Sent Events
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Wiz
CVE-2026-22735 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2026-22735 [MEDIUM] CVE-2026-22735 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22735 :
Apache Log4j vulnerability analysis and mitigation
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Source : NVD
## 2.6
Score
Published March 20, 2026
Severity LOW
CNA Score 2.6
Affected Technologies
Apache Log4j
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kafbat-ui
kafbat-ui-fips
Sources
NVD
Chainguard Has Fix Added at: Mar 29, 2026
Debian 11, 12, 13, 14 Severity LOW No Fix
Wiz
CVE-2026-22737 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2026-22737 [MEDIUM] CVE-2026-22737 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22737 :
Apache Log4j vulnerability analysis and mitigation
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Source : NVD
## 5.9
Score
Published March 20, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Apache Log4j
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
log4j:
2026-03-20
Published