Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41840

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.

A flaw was found in Spring WebFlux applications. A remote attacker could exploit this vulnerability by sending specially crafted multipart requests, leading to a Denial of Service (DoS) condition. This could make the application unavailable to legitimate users.

Отчет

Red Hat ships Spring WebFlux in Fuse 7. The affected version is set to AFFECTED/DEFER as the CVSS score (5.9) is below the 7.0 threshold for immediate remediation.

Меры по смягчению последствий

No specific mitigation is available. Restrict access to multipart request endpoints where possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7spring-webfluxFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2486722Spring Framework: Spring WebFlux: Denial of Service via multipart request processing

EPSS

Процентиль: 19%
0.00267
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.

CVSS3: 5.9
nvd
3 месяца назад

Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.

CVSS3: 5.9
debian
3 месяца назад

Spring WebFlux applications are vulnerable to Denial of Service (DoS) ...

CVSS3: 5.9
github
3 месяца назад

Spring Framework Denial of Service via Multipart Requests in WebFlux

EPSS

Процентиль: 19%
0.00267
Низкий

5.9 Medium

CVSS3