Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-22741

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true:

  • the application is using Spring MVC or Spring WebFlux
  • the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title  with caching enabled
  • the application adds support for encoded resources resolution
  • the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

    A flaw was found in Spring MVC and Spring WebFlux applications. A remote attacker can exploit this vulnerability by sending malicious requests to poison the resource cache with incorrectly encoded resources. This can lead to a denial of service (DoS) by disrupting the front-end application for clients. This vulnerability occurs when the application uses resource chain support with caching enabled, supports encoded resource resolution, and the resource cache is empty.

Меры по смягчению последствий

To mitigate this issue, applications utilizing Spring MVC or Spring WebFlux should disable resource chain support caching or encoded resource resolution if these features are not essential for their operation. Consult Spring Framework documentation for specific configuration details. A restart of the affected application will be required for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7spring-webmvcFix deferred
Red Hat build of Apache Camel for Spring Boot 4spring-webmvcFix deferred
Red Hat build of Apache Camel - HawtIO 4spring-webfluxFix deferred
Red Hat build of Apache Camel - HawtIO 4spring-webmvcFix deferred
Red Hat build of OptaPlanner 8spring-webmvcFix deferred
Red Hat Data Grid 8spring-webmvcFix deferred
Red Hat Enterprise Linux 8log4j:2/log4jFix deferred
Red Hat Enterprise Linux 8pki-core:10.6/resteasyFix deferred
Red Hat Enterprise Linux 8pki-deps:10.6/resteasyFix deferred
Red Hat Enterprise Linux 9log4jOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-838
https://bugzilla.redhat.com/show_bug.cgi?id=2463788Spring MVC: Spring WebFlux: Spring MVC and Spring WebFlux: Denial of Service via cache poisoning

EPSS

Процентиль: 15%
0.00236
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

CVSS3: 3.1
nvd
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title  with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

CVSS3: 3.1
debian
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning ...

CVSS3: 3.1
github
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

EPSS

Процентиль: 15%
0.00236
Низкий

5.9 Medium

CVSS3