Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41849

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 5.9

Описание

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

A flaw was found in the Spring Expression Language (SpEL) within the Spring Framework. An integer overflow vulnerability allows a remote attacker to supply a specially crafted SpEL expression. This can trigger excessive resource consumption, leading to a Denial of Service (DoS) condition.

Отчет

A flaw was found in Spring Framework. An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). This vulnerability only affects Spring Framework 5.3.48 and earlier versions. The 6.x branch is not affected. Example:

ExpressionParser parser = new SpelExpressionParser(); Expression exp = parser.parseExpression(<user-controlled-data>);

In order to be exploitable, an application is required to accept and evaluate untrusted (user-controlled) SpEL expressions. Thus AC:H.

Меры по смягчению последствий

Applications that don't evaluate user-controlled SpEL expressions are not affected. Users of affected versions should upgrade to the corresponding fixed version.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and Servicesspring-expressionNot affected
Red Hat OpenShift Dev Spacesspring-expressionNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2486710spring-framework: Spring Framework: Denial of Service via integer overflow in SpEL

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 7.5
nvd
около 2 месяцев назад

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 7.5
debian
около 2 месяцев назад

An integer overflow vulnerability exists in the evaluation logic of th ...

CVSS3: 7.5
github
около 2 месяцев назад

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

5.9 Medium

CVSS3