Acceptance of Extraneous Untrusted Data With Trusted Data in Pivotal Spring Framework - CVE-2026-22741
Published: April 21, 2026
Pivotal Spring Framework
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper cache control in static resource resolution when handling malicious requests for encoded resources. A remote attacker can send malicious requests to cause a denial of service.
Exploitation requires resource chain support with caching enabled, encoded resource resolution enabled, and an empty resource cache.