CVE-2026-22741
published 2026-04-29CVE-2026-22741: Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when…
PriorityP410low3.1CVSS 3.1
AVNACHPRNUIRSUCNINAL
EPSS
0.24%
14.6th percentile
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4j | — | — |
| devspaces | openvsx-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| log4j_2 | log4j | — | — |
| pki-core_10.6 | resteasy | — | — |
| pki-deps_10.6 | resteasy | — | — |
| redhat | resteasy | — | — |
| vmware | spring_framework | < 5.3.48 | 5.3.48 |
| vmware | spring_framework | >= 5.3.0 < 5.3.48 | 5.3.48 |
| vmware | spring_framework | >= 6.1.0 < 6.1.27 | 6.1.27 |
| vmware | spring_framework | >= 6.2.0 < 6.2.18 | 6.2.18 |
| vmware | spring_framework | >= 7.0.0 < 7.0.7 | 7.0.7 |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spring MVC: Spring WebFlux: Spring MVC and Spring WebFlux: Denial of Service via cache poisoning
vendor_redhat·2026-04-29·CVSS 3.1
CVE-2026-22741 [LOW] CWE-838 Spring MVC: Spring WebFlux: Spring MVC and Spring WebFlux: Denial of Service via cache poisoning
Spring MVC: Spring WebFlux: Spring MVC and Spring WebFlux: Denial of Service via cache poisoning
A flaw was found in Spring MVC and Spring WebFlux applications. A remote attacker can exploit this vulnerability by sending malicious requests to poison the resource cache with incorrectly encoded resources. This can lead to a denial of service (DoS) by disrupting the front-end application for clients. This vulnerability occurs when the application uses resource chain support with caching enabled, supports encoded resource resolution, and the resource cache is empty.
Mitigation: To mitigate this issue, applications utilizing Spring MVC or Spring WebFlux should disable resource chain support caching or encoded resource resolution if these features are not essential for their operation. Consult
VulDB
Vmware Spring Framework up to 5.3.47/6.1.26/6.2.17/7.0.6 MVC/WebFlux cache containing sensitive information (EUVD-2026-26206)
vuldb·2026-04-29·CVSS 3.1
CVE-2026-22741 [LOW] Vmware Spring Framework up to 5.3.47/6.1.26/6.2.17/7.0.6 MVC/WebFlux cache containing sensitive information (EUVD-2026-26206)
A vulnerability marked as problematic has been reported in Vmware Spring Framework up to 5.3.47/6.1.26/6.2.17/7.0.6. This issue affects some unknown processing of the component MVC/WebFlux. This manipulation causes use of cache containing sensitive information.
This vulnerability appears as CVE-2026-22741. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
ghsa·2026-04-29
CVE-2026-22741 [LOW] CWE-524 Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
More precisely, an application can be vulnerable when all the following are true:
* the application is using Spring MVC or Spring WebFlux
* the application is configuring the resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title with caching enabled
* the application adds support for encoded resources resolution
* the resource cache must be empty when the attacker has access to the application
When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with re
No detection rules found.
No public exploits indexed.
2026-04-29
Published