CVE-2026-41842: Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41842?
CVE-2026-41842 has a severity rating of high, with a score of 7.5.
What vulnerability does CVE-2026-41842 address?
CVE-2026-41842 addresses a Denial of Service (DoS) vulnerability in Spring MVC and WebFlux due to improper handling of versioned static resources.
How do I fix CVE-2026-41842?
To fix CVE-2026-41842, upgrade your Spring Framework to a version beyond 7.0.7, 6.2.18, 6.1.27, or 5.3.48.
What are the affected versions for CVE-2026-41842?
The affected versions for CVE-2026-41842 include Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.
Can CVE-2026-41842 lead to data loss?
While CVE-2026-41842 is primarily a Denial of Service vulnerability, it can result in service unavailability, impacting data access.