CVE-2026-41840: Spring Framework Denial of Service via Multipart Requests in WebFlux
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41840?
CVE-2026-41840 has a medium severity rating of 5.9.
How do I fix CVE-2026-41840?
To mitigate CVE-2026-41840, upgrade to Spring Framework versions 7.0.8 or later, 6.2.19 or later, 6.1.28 or later, or 5.3.49 or later.
What type of vulnerability is CVE-2026-41840?
CVE-2026-41840 is a Denial of Service (DoS) vulnerability affecting Spring WebFlux applications.
Which versions of Spring Framework are affected by CVE-2026-41840?
Affected versions include Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.
What impact does CVE-2026-41840 have?
CVE-2026-41840 allows attackers to exploit vulnerabilities in multipart requests, potentially leading to service disruptions.