CVE-2026-41853
published 2026-06-09CVE-2026-41853: Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.19%
8.4th percentile
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_framework | >= 5.3.0 < 5.3.49 | 5.3.49 |
| spring | spring_framework | >= 6.1.0 < 6.1.28 | 6.1.28 |
| spring | spring_framework | >= 6.2.0 < 6.2.18.1 | 6.2.18.1 |
| spring | spring_framework | >= 7.0.0 < 7.0.7.1 | 7.0.7.1 |
| vmware | spring_framework | >= 5.3.0 < 5.3.49 | 5.3.49 |
| vmware | spring_framework | >= 6.1.0 < 6.1.28 | 6.1.28 |
| vmware | spring_framework | >= 6.2.0 < 6.2.18.1 | 6.2.18.1 |
| vmware | spring_framework | >= 7.0.0 < 7.0.7.1 | 7.0.7.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spring Framework: Spring Framework: Request smuggling vulnerability in Spring MVC and WebFlux
vendor_redhat·2026-06-09·CVSS 5.3
CVE-2026-41853 [MEDIUM] CWE-444 Spring Framework: Spring Framework: Request smuggling vulnerability in Spring MVC and WebFlux
Spring Framework: Spring Framework: Request smuggling vulnerability in Spring MVC and WebFlux
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
A flaw was found in Spring MVC and WebFlux applications, components of the Spring Framework. This vulnerability allows a remote, unauthenticated attacker to perform Multipart request smuggling attacks. Such an attack can lead to a low integrity impact, potentially enabling the attacker to bypass security controls or modify data.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising
GHSA
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
ghsa_unreviewed·2026-06-09
CVE-2026-41853 [MEDIUM] CWE-444 Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
No detection rules found.
No public exploits indexed.
2026-06-09
Published