CVE-2026-41842
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Description
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
In plain language
AI Worth attentionIf your business uses Spring Framework versions 5.3.0–5.3.48, 6.1.0–6.1.27, 6.2.0–6.2.18, or 7.0.0–7.0.7 and is configured to resolve versioned static resources, attackers can send crafted web requests to make your app run out of resources and become unresponsive.
Unauthenticated Denial of Service is possible in Spring Framework via specially crafted requests that cause resource-intensive operations while resolving versioned static resources in Spring MVC/WebFlux; fixed versions are 7.0.7.1, 6.2.18.1, 6.1.28, and 5.3.49.
What to do now
- Check which Spring Framework version your application uses, and whether you configure Spring MVC or WebFlux to resolve versioned static resources.
- If you are on 7.0.0–7.0.7, plan to upgrade to 7.0.7.1.
- If you are on 6.2.0–6.2.18, plan to upgrade to 6.2.18.1.
- If you are on 6.1.0–6.1.27, plan to upgrade to 6.1.28.
- If you are on 5.3.0–5.3.48, plan to upgrade to 5.3.49.
- After upgrading, test that static asset delivery (versioned resources) still works as expected.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-41842 and every CVE in our database. Create a free account — no credit card required.
Create Free Account