CVE-2026-22745
published 2026-04-29CVE-2026-22745: Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.34%
26.6th percentile
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | spring_framework | < 5.3.48 | 5.3.48 |
| vmware | spring_framework | >= 5.3.0 < 5.3.48 | 5.3.48 |
| vmware | spring_framework | >= 6.1.0 < 6.1.27 | 6.1.27 |
| vmware | spring_framework | >= 6.2.0 < 6.2.18 | 6.2.18 |
| vmware | spring_framework | >= 7.0.0 < 7.0.7 | 7.0.7 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
ghsa·2026-04-29
CVE-2026-22745 [MEDIUM] CWE-400 Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources.
More precisely, an application can be vulnerable when all the following are true:
* the application is using Spring MVC or Spring WebFlux
* the application is serving static resources from the file system
* the application is running on a Windows platform
When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.
VulDB
Vmware Spring Framework up to 5.3.47/6.1.26/6.2.17/7.0.6 on Windows MVC/WebFlux resource consumption (EUVD-2026-26207)
vuldb·2026-04-29·CVSS 5.3
CVE-2026-22745 [MEDIUM] Vmware Spring Framework up to 5.3.47/6.1.26/6.2.17/7.0.6 on Windows MVC/WebFlux resource consumption (EUVD-2026-26207)
A vulnerability described as problematic has been identified in Vmware Spring Framework up to 5.3.47/6.1.26/6.2.17/7.0.6 on Windows. Impacted is an unknown function of the component MVC/WebFlux. Such manipulation leads to resource consumption.
This vulnerability is traded as CVE-2026-22745. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
Red Hat
spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on Windows
vendor_redhat·2026-04-29·CVSS 5.3
CVE-2026-22745 [MEDIUM] CWE-770 spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on Windows
spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on Windows
A flaw was found in Spring MVC and Spring WebFlux applications. When an application is configured to serve static resources from the file system on a Windows platform, a remote attacker can send specially crafted requests that are slow to resolve. This can keep HTTP connections in use, leading to a Denial of Service (DoS) on the application.
Package: spring-webflux (Red Hat build of Apache Camel - HawtIO 4) - Fix deferred
Package: spring-webflux (Red Hat Fuse 7) - Out of support scope
Package: spring-webflux (Red Hat JBoss Enterprise Application Platform 7) - Out of support scope
Package: opentelemetry-javaagent-spring-webflux-5.0 (Red Hat JBoss Enterprise Application Platfo
No detection rules found.
No public exploits indexed.
2026-04-29
Published