Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41842

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 5.9

Описание

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

A flaw was found in the Spring Framework. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by exploiting how Spring MVC and WebFlux applications resolve static resources. This can lead to the affected application becoming unavailable.

Отчет

A flaw was found in Spring Framework. Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources with versioned resources support configured. An attacker can send malicious requests that are slow to resolve and keep HTTP connections in use, potentially leading to application unavailability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and Servicesspring-webFix deferred
Red Hat OpenShift Dev Spacesspring-webFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2486717spring-framework: Spring Framework: Denial of Service when resolving static resources

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 7.5
nvd
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 7.5
debian
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Denial of Servic ...

CVSS3: 7.5
github
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

5.9 Medium

CVSS3