CVE-2026-41853: Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
Published Jun 9, 2026
·Updated
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected Software
7 affected components
Spring Spring Framework>=7.0.0<=7.0.7, >=6.2.0<=6.2.18, >=6.1.0<=6.1.27, >=5.3.0<=5.3.48
VMware Spring Framework>=5.3.0<5.3.49
VMware Spring Framework>=6.1.0<6.1.28
VMware Spring Framework>=6.2.0<6.2.18.1
VMware Spring Framework>=7.0.0<7.0.7.1
IBM Engineering Requirements Management DOORS and DOORS Web Access<=9.7.2.1 - 9.7.2.11
IBM Engineering Requirements Management DOORS and DOORS Web Access<=9.6.1.1 - 9.6.1.13
Event History
Jun 9, 2026
CVE Published
via MITRE·03:51 AM
Data Sourced
via MITRE·03:51 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Jul 6, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-41853?
The severity of CVE-2026-41853 is classified as medium with a CVSS score of 5.3.
2
How do I fix CVE-2026-41853?
To fix CVE-2026-41853, upgrade the Spring Framework to versions later than 7.0.7, 6.2.18, 6.1.27, or 5.3.48.
3
What types of applications are affected by CVE-2026-41853?
CVE-2026-41853 affects applications built using the Spring MVC and WebFlux frameworks.
4
What are the implications of CVE-2026-41853?
The implications of CVE-2026-41853 include vulnerability to multipart request smuggling attacks, which can lead to unauthorized data manipulation.
5
When was CVE-2026-41853 published?
CVE-2026-41853 was published on June 9, 2026.