Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41852

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

A flaw was found in Spring Framework. A vulnerability in the Spring Expression Language (SpEL) evaluation logic allows an attacker to invoke arbitrary zero-argument methods, even in restricted contexts. This can lead to the execution of unintended application logic, potentially resulting in a Denial of Service (DoS).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Fix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Fix deferred
Red Hat AMQ Clientsspring-expressionFix deferred
Red Hat build of Apache Camel 4 for Quarkus 3spring-expressionFix deferred
Red Hat build of Apache Camel - HawtIO 4spring-expressionFix deferred
Red Hat Data Grid 8spring-expressionFix deferred
Red Hat Enterprise Linux 8log4j:2/log4jFix deferred
Red Hat Fuse 7spring-expressionFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packspring-expressionFix deferred
Red Hat OpenShift Dev Spacesdevspaces/openvsx-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-917
https://bugzilla.redhat.com/show_bug.cgi?id=2486721spring-framework: org.springframework/spring-expression: Spring Framework: SpEL vulnerability allows unintended application logic invocation

EPSS

Процентиль: 8%
0.00177
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 2 месяцев назад

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 3.7
nvd
около 2 месяцев назад

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 3.7
debian
около 2 месяцев назад

A vulnerability in Spring Expression Language (SpEL) evaluation logic ...

CVSS3: 3.7
github
около 2 месяцев назад

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

EPSS

Процентиль: 8%
0.00177
Низкий

3.7 Low

CVSS3