CVE-2026-41849
published 2026-06-09CVE-2026-41849: An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.26%
17.9th percentile
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS).
Affected versions:
Spring Framework 5.3.0 through 5.3.48.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_framework | >= 5.3.0 < 5.3.49 | 5.3.49 |
| vmware | spring_framework | >= 5.3.0 < 5.3.49 | 5.3.49 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL).
ghsa_unreviewed·2026-06-09
CVE-2026-41849 [HIGH] CWE-190 An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL).
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS).
Affected versions:
Spring Framework 5.3.0 through 5.3.48.
Red Hat
spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL
vendor_redhat·2026-06-09·CVSS 7.5
CVE-2026-41849 [HIGH] CWE-190 spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL
spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS).
Affected versions:
Spring Framework 5.3.0 through 5.3.48.
A flaw was found in the Spring Expression Language (SpEL) within the Spring Framework. An integer overflow vulnerability allows a remote attacker to supply a specially crafted SpEL expression. This can trigger excessive resource consumption, leading to a Denial of Service (DoS) condition.
Statement: A flaw was found in Spring Framework. An integer overflow vulnerability exists in th
No detection rules found.
No public exploits indexed.
2026-06-09
Published