CVE-2026-22740
published 2026-04-29CVE-2026-22740: A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.34%
26.8th percentile
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space.
Older, unsupported versions are also affected.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | spring_framework | < 5.3.48 | 5.3.48 |
| vmware | spring_framework | >= 5.3.0 < 5.3.48 | 5.3.48 |
| vmware | spring_framework | >= 6.1.0 < 6.1.27 | 6.1.27 |
| vmware | spring_framework | >= 6.2.0 < 6.2.18 | 6.2.18 |
| vmware | spring_framework | >= 7.0.0 < 7.0.7 | 7.0.7 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
spring-webflux: Spring WebFlux: Denial of Service via temporary file accumulation
vendor_redhat·2026-04-29·CVSS 6.5
CVE-2026-22740 [MEDIUM] CWE-459 spring-webflux: Spring WebFlux: Denial of Service via temporary file accumulation
spring-webflux: Spring WebFlux: Denial of Service via temporary file accumulation
A flaw was found in Spring WebFlux, a component of the Spring Framework. A remote attacker can exploit this vulnerability by sending specially crafted multipart requests to a WebFlux server application. When processing these requests, the server creates temporary files that, under certain conditions, are not properly deleted. This can lead to an accumulation of temporary files, consuming available disk space and potentially causing a Denial of Service (DoS) for the affected system.
Package: spring-webflux (Red Hat build of Apache Camel - HawtIO 4) - Fix deferred
Package: spring-webflux (Red Hat Fuse 7) - Out of support scope
Package: spring-webflux (Red Hat JBoss Enterprise Application Platform 7) - Out o
GHSA
Spring Framework DoS with Multipart Temp Files in WebFlux
ghsa·2026-04-29
CVE-2026-22740 [LOW] CWE-400 Spring Framework DoS with Multipart Temp Files in WebFlux
Spring Framework DoS with Multipart Temp Files in WebFlux
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space.
Older, unsupported versions are also affected.
VulDB
Vmware Spring Framework up to 5.3.47/6.1.26/6.2.17/7.0.6 Multipart Request resource consumption
vuldb·2026-04-29·CVSS 6.5
CVE-2026-22740 [MEDIUM] Vmware Spring Framework up to 5.3.47/6.1.26/6.2.17/7.0.6 Multipart Request resource consumption
A vulnerability, which was classified as problematic, was found in Vmware Spring Framework up to 5.3.47/6.1.26/6.2.17/7.0.6. The affected element is an unknown function of the component Multipart Request Handler. Executing a manipulation can lead to resource consumption.
The identification of this vulnerability is CVE-2026-22740. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-04-29
Published