CVE-2026-59282
published 2026-08-27CVE-2026-59282: Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.32%
25.2th percentile
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_framework | <= 5.2.25.RELEASE | — |
| spring | spring_framework | 5.3.0 – 5.3.49 | — |
| spring | spring_framework | 6.0.0 – 6.0.30 | — |
| spring | spring_framework | 6.1.0 – 6.1.28 | — |
| spring | spring_framework | 6.2.0 – 6.2.19 | — |
| spring | spring_framework | 7.0.0 – 7.0.8 | — |
| vmware | spring_framework | < 5.2.26 | 5.2.26 |
| vmware | spring_framework | >= 5.3.0 < 5.3.50 | 5.3.50 |
| vmware | spring_framework | >= 6.0.0 < 6.0.31 | 6.0.31 |
| vmware | spring_framework | >= 6.1.0 < 6.1.29 | 6.1.29 |
| vmware | spring_framework | >= 6.2.0 < 6.2.20 | 6.2.20 |
| vmware | spring_framework | >= 7.0.0 < 7.0.8.1 | 7.0.8.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
VMware Spring Framework up to 7.0.8 Data Binding resource consumption (WID-SEC-2026-2955)
vuldb·2026-08-27·CVSS 7.5
CVE-2026-59282 [HIGH] VMware Spring Framework up to 7.0.8 Data Binding resource consumption (WID-SEC-2026-2955)
A vulnerability was found in VMware Spring Framework up to 7.0.8. It has been classified as problematic. The impacted element is an unknown function of the component Data Binding. The manipulation leads to resource consumption.
This vulnerability is traded as CVE-2026-59282. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack.
ghsa_unreviewed·2026-08-27
CVE-2026-59282 [HIGH] CWE-400 Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack.
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-27
Published