CVE-2026-41842
published 2026-06-09CVE-2026-41842: Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.40%
32.5th percentile
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_framework | >= 5.3.0 < 5.3.49 | 5.3.49 |
| spring | spring_framework | >= 6.1.0 < 6.1.28 | 6.1.28 |
| spring | spring_framework | >= 6.2.0 < 6.2.18.1 | 6.2.18.1 |
| spring | spring_framework | >= 7.0.0 < 7.0.7.1 | 7.0.7.1 |
| vmware | spring_framework | >= 5.3.0 < 5.3.49 | 5.3.49 |
| vmware | spring_framework | >= 6.1.0 < 6.1.28 | 6.1.28 |
| vmware | spring_framework | >= 6.2.0 < 6.2.18.1 | 6.2.18.1 |
| vmware | spring_framework | >= 7.0.0 < 7.0.7.1 | 7.0.7.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
ghsa_unreviewed·2026-06-09
CVE-2026-41842 [HIGH] CWE-400 Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Red Hat
spring-framework: Spring Framework: Denial of Service when resolving static resources
vendor_redhat·2026-06-09·CVSS 7.5
CVE-2026-41842 [HIGH] CWE-770 spring-framework: Spring Framework: Denial of Service when resolving static resources
spring-framework: Spring Framework: Denial of Service when resolving static resources
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
A flaw was found in the Spring Framework. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by exploiting how Spring MVC and WebFlux applications resolve static resources. This can lead to the affected application becoming unavailable.
Statement: A flaw was found in Spring Framework. Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources with versioned resources support conf
No detection rules found.
No public exploits indexed.
2026-06-09
Published