Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wg35-8jpf-2xv3

Опубликовано: 29 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

More precisely, an application can be vulnerable when all the following are true:

When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

Пакеты

Наименование

org.springframework:spring-webflux

maven
Затронутые версииВерсия исправления

>= 7.0.0, <= 7.0.6

7.0.7

Наименование

org.springframework:spring-webflux

maven
Затронутые версииВерсия исправления

>= 6.2.0, <= 6.2.17

6.2.18

Наименование

org.springframework:spring-webflux

maven
Затронутые версииВерсия исправления

>= 6.1.0, <= 6.1.26

Отсутствует

Наименование

org.springframework:spring-webflux

maven
Затронутые версииВерсия исправления

<= 5.3.47

Отсутствует

Наименование

org.springframework:spring-webmvc

maven
Затронутые версииВерсия исправления

>= 7.0.0, <= 7.0.6

7.0.7

Наименование

org.springframework:spring-webmvc

maven
Затронутые версииВерсия исправления

>= 6.2.0, <= 6.2.17

6.2.18

Наименование

org.springframework:spring-webmvc

maven
Затронутые версииВерсия исправления

>= 6.1.0, <= 6.1.26

Отсутствует

Наименование

org.springframework:spring-webmvc

maven
Затронутые версииВерсия исправления

<= 5.3.47

Отсутствует

EPSS

Процентиль: 15%
0.00236
Низкий

3.1 Low

CVSS3

Дефекты

CWE-524

Связанные уязвимости

CVSS3: 3.1
ubuntu
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

CVSS3: 5.9
redhat
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title  with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

CVSS3: 3.1
nvd
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title  with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

CVSS3: 3.1
debian
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning ...

EPSS

Процентиль: 15%
0.00236
Низкий

3.1 Low

CVSS3

Дефекты

CWE-524