Allocation of Resources Without Limits or Throttling in Spring Framework - CVE-2026-47891
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Jaxb2Decoder when parsing XML input with the Aalto XML processor. A remote attacker can send specially crafted XML content to cause a denial of service.
The issue affects Spring WebFlux applications that rely on the Aalto XML processor for XML parsing.
Affected software
Library Support for Spring
How to mitigate CVE-2026-47891
Library Support for Spring - update to 3.5.19