Improper Resource Shutdown or Release in Spring Framework - CVE-2026-22740
Published: April 21, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper resource management in multipart request handling in WebFlux when processing multipart requests. A remote user can send a series of multipart requests to consume available disk space.
Temp files created for parts larger than 10 K may remain undeleted after request processing under some circumstances.
Affected software
Db2 Developer Extension
IBM Sterling Connect:Direct Web Services
Library Support for Spring
How to mitigate CVE-2026-22740
Db2 Developer Extension - update to 1.1.2
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
Library Support for Spring - update to 2.7.38