Resource exhaustion in Spring Framework - CVE-2026-22745

 

Resource exhaustion in Spring Framework - CVE-2026-22745

Published: April 21, 2026


Vulnerability identifier: #VU126710
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-22745
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in static resource handling when resolving static resources from the file system on Windows platforms. A remote attacker can send malicious requests that are slow to resolve to cause a denial of service.

The issue affects applications using Spring MVC or Spring WebFlux that serve static resources from the file system on Windows platforms.


Affected software

Spring Framework
IBM Sterling Connect:Direct Web Services
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Library Support for Spring

How to mitigate CVE-2026-22745

Install security update from vendor's website.

Spring Framework - addressed in versions 5.3.48, 6.1.27, 6.2.18, 7.0.7
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
Library Support for Spring - update to 2.7.38

External References

Related Security Bulletins