Resource exhaustion in Spring Framework - CVE-2026-41842

 

Resource exhaustion in Spring Framework - CVE-2026-41842

Published: August 28, 2026


Vulnerability identifier: #VU146170
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41842
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in static resource resolution in Spring MVC and Spring WebFlux when resolving versioned resources served from the file system. A remote attacker can send malicious requests that are slow to resolve to cause a denial of service.

Only applications that serve static resources from the file system and have versioned resources support configured are vulnerable.


Affected software

Spring Framework
Crowd Data Center
Jira Service Management Data Center
Jira Software Data Center
Bamboo Data Center

How to mitigate CVE-2026-41842

Install security update from vendor's website.

Spring Framework - addressed in versions 5.3.49, 6.1.28, 6.2.18.1, 6.2.19, 7.0.7.1, 7.0.8
Crowd Data Center - update to 7.2.2
Jira Service Management Data Center - update to 11.3.8
Jira Software Data Center - update to 11.3.8
Bamboo Data Center - update to 12.1.10

External References

Related Security Bulletins