Resource exhaustion in Pivotal Spring Framework - CVE-2026-22745
Published: April 21, 2026
Pivotal Spring Framework
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in static resource handling when resolving static resources from the file system on Windows platforms. A remote attacker can send malicious requests that are slow to resolve to cause a denial of service.
The issue affects applications using Spring MVC or Spring WebFlux that serve static resources from the file system on Windows platforms.