Allocation of Resources Without Limits or Throttling in Spring Framework - CVE-2026-47891

 

Allocation of Resources Without Limits or Throttling in Spring Framework - CVE-2026-47891

Published: August 28, 2026


Vulnerability identifier: #VU146224
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47891
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in Jaxb2Decoder when parsing XML input with the Aalto XML processor. A remote attacker can send specially crafted XML content to cause a denial of service.

The issue affects Spring WebFlux applications that rely on the Aalto XML processor for XML parsing.


Affected software

Spring Framework
Library Support for Spring

How to mitigate CVE-2026-47891

Install security update from vendor's website.

Spring Framework - addressed in versions 5.2.26, 5.3.50, 6.0.31, 6.1.29, 6.2.20, 7.0.8.1, 7.0.9
Library Support for Spring - update to 3.5.19

External References

Related Security Bulletins