CVE-2026-59282: Spring Framework Denial of Service via Unbounded List Growth in Data Binding
Published Aug 27, 2026
·Updated
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Affected Software
6 affected components
Spring Spring Framework>=7.0.0<=7.0.8
Spring Spring Framework>=6.2.0<=6.2.19
Spring Spring Framework>=6.1.0<=6.1.28
Spring Spring Framework>=6.0.0<=6.0.30
Spring Spring Framework>=5.3.0<=5.3.49
Spring Spring Framework<5.2.25.RELEASE
Event History
Aug 27, 2026
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Which Spring Framework release lines are within the stated affected ranges?
The stated ranges are 7.0.0 through 7.0.8, 6.2.0 through 6.2.19, 6.1.0 through 6.1.28, 6.0.0 through 6.0.30, 5.3.0 through 5.3.49, and 5.2.25.RELEASE and earlier.