CVE-2026-41840
published 2026-06-09CVE-2026-41840: Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0…
PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.27%
18.6th percentile
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.
Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_framework | >= 5.3.0 < 5.3.49 | 5.3.49 |
| spring | spring_framework | >= 6.1.0 < 6.1.28 | 6.1.28 |
| spring | spring_framework | >= 6.2.0 < 6.2.18.1 | 6.2.18.1 |
| spring | spring_framework | >= 7.0.0 < 7.0.7.1 | 7.0.7.1 |
| vmware | spring_framework | >= 5.3.0 < 5.3.49 | 5.3.49 |
| vmware | spring_framework | >= 6.1.0 < 6.1.28 | 6.1.28 |
| vmware | spring_framework | >= 6.2.0 < 6.2.18.1 | 6.2.18.1 |
| vmware | spring_framework | >= 7.0.0 < 7.0.7.1 | 7.0.7.1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spring Framework: Spring WebFlux: Denial of Service via multipart request processing
vendor_redhat·2026-06-09·CVSS 5.9
CVE-2026-41840 [MEDIUM] CWE-770 Spring Framework: Spring WebFlux: Denial of Service via multipart request processing
Spring Framework: Spring WebFlux: Denial of Service via multipart request processing
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.
Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
A flaw was found in Spring WebFlux applications. A remote attacker could exploit this vulnerability by sending specially crafted multipart requests, leading to a Denial of Service (DoS) condition. This could make the application unavailable to legitimate users.
Statement: Red Hat ships Spring WebFlux in Fuse 7. The affected version is set to AFFECTED/DEFER as the CVSS score (5.9) is below the 7.0 threshold for immediate remediation.
Mitigation: No specific mitigation is
GHSA
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.
ghsa_unreviewed·2026-06-09
CVE-2026-41840 [MEDIUM] CWE-400 Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA
Spring Framework Denial of Service via Multipart Requests in WebFlux
ghsa·2026-06-09
CVE-2026-41840 [MEDIUM] CWE-400 Spring Framework Denial of Service via Multipart Requests in WebFlux
Spring Framework Denial of Service via Multipart Requests in WebFlux
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
No detection rules found.
No public exploits indexed.
2026-06-09
Published