Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-22745

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 5.3

Описание

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true:

  • the application is using Spring MVC or Spring WebFlux
  • the application is serving static resources from the file system
  • the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.

    A flaw was found in Spring MVC and Spring WebFlux applications. When an application is configured to serve static resources from the file system on a Windows platform, a remote attacker can send specially crafted requests that are slow to resolve. This can keep HTTP connections in use, leading to a Denial of Service (DoS) on the application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel - HawtIO 4spring-webfluxFix deferred
Red Hat Fuse 7spring-webfluxOut of support scope
Red Hat JBoss Enterprise Application Platform 7spring-webfluxOut of support scope
Red Hat JBoss Enterprise Application Platform 8opentelemetry-javaagent-spring-webflux-5.0Fix deferred
Red Hat JBoss Enterprise Application Platform 8opentelemetry-spring-webflux-5.3Fix deferred
Red Hat JBoss Enterprise Application Platform 8spring-webfluxFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packopentelemetry-javaagent-spring-webflux-5.0Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packopentelemetry-spring-webflux-5.3Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packspring-webfluxOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2463790spring-webflux: Spring MVC and Spring WebFlux: Denial of Service via slow static resource resolution on Windows

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.

CVSS3: 5.3
debian
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to Denial of Servic ...

CVSS3: 5.3
github
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources

5.3 Medium

CVSS3