Resource exhaustion in Spring Framework - CVE-2026-41842
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in static resource resolution in Spring MVC and Spring WebFlux when resolving versioned resources served from the file system. A remote attacker can send malicious requests that are slow to resolve to cause a denial of service.
Only applications that serve static resources from the file system and have versioned resources support configured are vulnerable.
Affected software
Crowd Data Center
Jira Service Management Data Center
Jira Software Data Center
Bamboo Data Center
How to mitigate CVE-2026-41842
Crowd Data Center - update to 7.2.2
Jira Service Management Data Center - update to 11.3.8
Jira Software Data Center - update to 11.3.8
Bamboo Data Center - update to 12.1.10