CRLF injection in Spring Framework - CVE-2026-47890
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to corrupt the stream of data sent to other users.
The vulnerability exists due to improper neutralization of carriage return line feeds in server-sent event view fragment rendering when streaming attacker-controlled data to clients over server-sent events. A remote user can control data that is streamed to other users to corrupt the stream of data sent to other users.
Exploitation requires the application to use Spring MVC or Spring WebFlux and send view fragments to clients over server-sent events.
Affected software
Library Support for Spring
How to mitigate CVE-2026-47890
Library Support for Spring - update to 3.5.19