CVE-2026-59313: Server Sent Event stream corruption in Spring MVC functional web framework
Published Aug 27, 2026
·Updated
Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49
Affected Software
1 affected component
Spring Spring Framework>=7.0.0<=7.0.8, >=6.2.0<=6.2.19, >=6.1.0<=6.1.28, >=6.0.0<=6.0.30, >=5.3.0<=5.3.49
Event History
Aug 27, 2026
CVE Published
via MITRE·05:58 PM
Data Sourced
via MITRE·05:58 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Which applications are exposed to this issue?
Spring MVC applications that use the functional web framework and Server-Sent Events are affected if they run a listed Spring Framework version: 7.0.0 through 7.0.8, 6.2.0 through 6.2.19, 6.1.0 through 6.1.28, 6.0.0 through 6.0.30, or 5.3.0 through 5.3.49.
2
Is a Spring MVC application affected if it does not use SSE endpoints?
The described issue applies to applications using Server-Sent Events in the Spring MVC functional web framework. The provided information does not indicate exposure for applications that do not use SSE.