Resource exhaustion in Spring Framework - CVE-2026-22745
Published: April 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in static resource handling when resolving static resources from the file system on Windows platforms. A remote attacker can send malicious requests that are slow to resolve to cause a denial of service.
The issue affects applications using Spring MVC or Spring WebFlux that serve static resources from the file system on Windows platforms.
Affected software
IBM Sterling Connect:Direct Web Services
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Library Support for Spring
How to mitigate CVE-2026-22745
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
Library Support for Spring - update to 2.7.38
External References
Related Security Bulletins
- Multiple vulnerabilities in Pivotal Spring Framework
- Multiple vulnerabilities in IBM Library Support for Spring
- IBM Sterling Connect:Direct Web Services update for Spring MVC and WebFlux
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in CICS Transaction Gateway Desktop Edition