Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-775g-4xr8-78h8

Опубликовано: 09 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Spring Framework Denial of Service via Integer Overflow in SpEL Expressions

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS).

Affected versions: Spring Framework 5.3.0 through 5.3.48.

Пакеты

Наименование

org.springframework:spring-expression

maven
Затронутые версииВерсия исправления

<= 5.3.39

Отсутствует

EPSS

Процентиль: 18%
0.00263
Низкий

7.5 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 5.9
redhat
3 месяца назад

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 7.5
nvd
3 месяца назад

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 7.5
debian
3 месяца назад

An integer overflow vulnerability exists in the evaluation logic of th ...

EPSS

Процентиль: 18%
0.00263
Низкий

7.5 High

CVSS3

Дефекты

CWE-190