Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41710

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in the application to fail. Affected versions: Spring Retry 2.0.0 through 2.0.12; 1.3.0 through 1.3.4.

A flaw was found in Spring Retry. A remote attacker can craft a large number of unique requests, leading to the exhaustion of the application-wide stateful retry cache. Once the cache is full, it permanently rejects further updates, causing all subsequent stateful retries and circuit breakers in the application to fail. This can result in a Denial of Service (DoS) for the application.

Отчет

Red Hat ships Spring Retry as a transitive dependency in several products. This flaw affects the stateful retry cache mechanism, where an attacker can exhaust the cache by sending a large volume of unique requests that trigger failures. Once exhausted, all subsequent stateful retries and circuit breakers permanently fail, resulting in a denial of service. However, exploitation requires high attack complexity as the attacker must craft many unique requests to fill the application-wide cache.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel 4 for Quarkus 3spring-retryFix deferred
Red Hat Data Grid 8spring-retryFix deferred
Red Hat Fuse 7spring-retryOut of support scope
Red Hat JBoss Enterprise Application Platform Expansion Packspring-retryOut of support scope
Red Hat OpenShift Dev Spacesdevspaces/openvsx-rhel9Fix deferred
Red Hat OpenShift Dev Spacesdevspaces/pluginregistry-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2486712spring-retry: Spring Retry: Denial of Service via cache exhaustion

EPSS

Процентиль: 20%
0.0028
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
2 месяца назад

An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in the application to fail. Affected versions: Spring Retry 2.0.0 through 2.0.12; 1.3.0 through 1.3.4.

CVSS3: 5.9
github
2 месяца назад

Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service

EPSS

Процентиль: 20%
0.0028
Низкий

5.9 Medium

CVSS3