CVE-2026-47891
published 2026-08-27CVE-2026-47891: A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.29%
21.4th percentile
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_framework | <= 5.2.25.RELEASE | — |
| spring | spring_framework | 5.3.0 – 5.3.49 | — |
| spring | spring_framework | 6.0.0 – 6.0.30 | — |
| spring | spring_framework | 6.1.0 – 6.1.28 | — |
| spring | spring_framework | 6.2.0 – 6.2.19 | — |
| spring | spring_framework | 7.0.0 – 7.0.8 | — |
| vmware | spring_framework | < 5.2.26 | 5.2.26 |
| vmware | spring_framework | >= 5.3.0 < 5.3.50 | 5.3.50 |
| vmware | spring_framework | >= 6.0.0 < 6.0.31 | 6.0.31 |
| vmware | spring_framework | >= 6.1.0 < 6.1.29 | 6.1.29 |
| vmware | spring_framework | >= 6.2.0 < 6.2.20 | 6.2.20 |
| vmware | spring_framework | >= 7.0.0 < 7.0.8.1 | 7.0.8.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Spring Framework up to 7.0.8 Aalto XML Processor allocation of resources (WID-SEC-2026-2955)
vuldb·2026-08-27·CVSS 9.8
CVE-2026-47891 [CRITICAL] Spring Framework up to 7.0.8 Aalto XML Processor allocation of resources (WID-SEC-2026-2955)
A vulnerability was found in Spring Framework up to 7.0.8. It has been classified as problematic. This affects an unknown part of the component Aalto XML Processor. This manipulation causes allocation of resources.
The identification of this vulnerability is CVE-2026-47891. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
ghsa_unreviewed·2026-08-27
CVE-2026-47891 [CRITICAL] CWE-770 A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Red Hat
org.springframework/spring-webflux: org.springframework/spring-web: Spring WebFlux: Denial of Service due to maxInMemorySize bypass
vendor_redhat·2026-08-27·CVSS 9.8
CVE-2026-47891 [CRITICAL] CWE-770 org.springframework/spring-webflux: org.springframework/spring-web: Spring WebFlux: Denial of Service due to maxInMemorySize bypass
org.springframework/spring-webflux: org.springframework/spring-web: Spring WebFlux: Denial of Service due to maxInMemorySize bypass
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
A flaw was found in Spring WebFlux applications that utilize the Aalto XML processor to parse XML input. A remote attacker could exploit this vulnerability by sending specially crafted XML, causing the application to bypass the maxInMemorySize limit. This can lead to excessive memory consumption, potentially resulting in
No detection rules found.
No public exploits indexed.
2026-08-27
Published