CVE-2026-41841: Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41841?
CVE-2026-41841 has a medium severity score of 5.9.
How do I fix CVE-2026-41841?
To fix CVE-2026-41841, update your Spring Framework to versions 7.0.8 or later, 6.2.19 or later, 6.1.28 or later, or 5.3.49 or later.
What type of vulnerability is CVE-2026-41841?
CVE-2026-41841 is an Information Disclosure vulnerability affecting Spring MVC and WebFlux applications.
Which versions of Spring Framework are affected by CVE-2026-41841?
Affected versions of Spring Framework include 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.
What can attackers achieve through CVE-2026-41841?
Attackers can exploit CVE-2026-41841 to gain unauthorized access to sensitive information through static resource caching.