Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41853

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

A flaw was found in Spring MVC and WebFlux applications, components of the Spring Framework. This vulnerability allows a remote, unauthenticated attacker to perform Multipart request smuggling attacks. Such an attack can lead to a low integrity impact, potentially enabling the attacker to bypass security controls or modify data.

Отчет

This Moderate-impact flaw in Spring MVC and WebFlux applications allows remote, unauthenticated attackers to conduct Multipart request smuggling. This can lead to bypassing security controls or modifying data, affecting the integrity of applications utilizing these Spring Framework components.

Меры по смягчению последствий

Users of affected versions should upgrade to the corresponding fixed version.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsFix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Fix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Fix deferred
OpenShift Developer Tools and Servicesspring-webFix deferred
Red Hat build of Apache Camel 4 for Quarkus 3spring-webFix deferred
Red Hat build of Apache Camel - HawtIO 4spring-webFix deferred
Red Hat Data Grid 8spring-webFix deferred
Red Hat Enterprise Linux 7xbeanFix deferred
Red Hat Enterprise Linux 8javapackages-tools:201801/xbeanFix deferred
Red Hat Enterprise Linux 8pki-core:10.6/resteasyFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2486708Spring Framework: Spring Framework: Request smuggling vulnerability in Spring MVC and WebFlux

EPSS

Процентиль: 8%
0.00186
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.3
nvd
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.3
debian
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Multipart reques ...

CVSS3: 5.3
github
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

EPSS

Процентиль: 8%
0.00186
Низкий

5.3 Medium

CVSS3