Allocation of Resources Without Limits or Throttling in Spring Framework - CVE-2026-59282
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Spring data binding infrastructure when applying user-supplied property paths onto a target object. A remote attacker can supply a property path with an arbitrarily large index into a nested sub-property to cause a denial of service.
Exploitation requires the target object to contain a self-populating list implementation as a property, and the list element type must expose sub-properties.
Affected software
Library Support for Spring
How to mitigate CVE-2026-59282
Library Support for Spring - update to 3.5.19