Improper Neutralization of Special Elements in Output Used by a Downstream Component in Spring Framework - CVE-2026-22735

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Spring Framework - CVE-2026-22735

Published: April 28, 2026


Vulnerability identifier: #VU128385
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-22735
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to corrupt data streams sent to other users.

The vulnerability exists due to improper neutralization of special elements in Server-Sent Events handling in Spring MVC and Spring WebFlux when streaming plain text Server-Sent Events to clients. A remote user can control data that is streamed to other users to corrupt data streams sent to other users.

The issue is exposed only when plain text messages are used instead of a structured format such as JSON, and user interaction is required.


Affected software

Spring Framework
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Library Support for Spring
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
MongoDB Enterprise Advanced with IBM
IBM Sterling Connect:Direct for Microsoft Windows

How to mitigate CVE-2026-22735

Install security update from vendor's website.

Spring Framework - addressed in versions 5.3.47, 6.1.26, 6.2.17, 7.0.6
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
MongoDB Enterprise Advanced with IBM - update to 1.16.0
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.45, 6.4.0.4.17

External References

Related Security Bulletins