CVE-2026-47890: Spring Framework Server Sent Event stream corruption while rendering fragments
Published Aug 27, 2026
·Updated
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Affected Software
2 affected components
Pivotal Software Spring Framework>=7.0.0<=7.0.8
Pivotal Software Spring Framework>=6.2.0<=6.2.19
Event History
Aug 27, 2026
CVE Published
via MITRE·05:21 AM
Data Sourced
via MITRE·05:21 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
Which applications are affected?
Spring MVC and WebFlux applications using Server-Sent Events together with view fragments are affected. The provided affected ranges are Spring Framework 7.0.0 through 7.0.8 and 6.2.0 through 6.2.19.
2
What configuration or feature use is required for exposure?
Exposure requires the application to use SSE while rendering view fragments. The data does not establish that applications not using both of these features are affected.