7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Basic Information
ID
CVE-2026-41850
Source
vmware
Published
Jun 9, 2026 at 03:51
Affected Product
Vendor
Spring
Product
Spring Framework
Version
7.0.0
Affected Versions
Spring Spring Framework 7.0.0
Spring Spring Framework 6.2.0
Spring Spring Framework 6.1.0
Spring Spring Framework 5.3.0
Spring Spring Framework 6.2.0
Spring Spring Framework 6.1.0
Spring Spring Framework 5.3.0