Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-22735

Опубликовано: 20 мар. 2026
Источник: nvd
CVSS3: 2.6
EPSS Низкий

Описание

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
Версия до 5.3.47 (исключая)
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
Версия от 6.1.0 (включая) до 6.1.26 (исключая)
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
Версия от 6.2.0 (включая) до 6.2.17 (исключая)
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.0.6 (исключая)

EPSS

Процентиль: 2%
0.00112
Низкий

2.6 Low

CVSS3

Дефекты

CWE-667

Связанные уязвимости

CVSS3: 2.6
ubuntu
4 месяца назад

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 2.6
redhat
4 месяца назад

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 2.6
debian
4 месяца назад

Spring MVC and WebFlux applications are vulnerable to stream corruptio ...

CVSS3: 2.6
github
4 месяца назад

Spring MVC and WebFlux has Server Sent Event stream corruption

EPSS

Процентиль: 2%
0.00112
Низкий

2.6 Low

CVSS3

Дефекты

CWE-667