CVE 6.5 MEDIUM

Spring Framework DoS with Multipart Temp Files in WebFlux_CVE-2026-22740

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Description

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space.

Older, unsupported versions are also affected.

Basic Information

ID CVE-2026-22740
Source vmware
Published Apr 29, 2026 at 10:46
Modified Apr 29, 2026 at 14:00

Affected Product

Vendor VMware
Product Spring Framework
Version 7.0.0
Affected Versions VMware Spring Framework 7.0.0
VMware Spring Framework 6.2.0
VMware Spring Framework 6.1.0
VMware Spring Framework 5.3.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.