Improper Control of Dynamically-Managed Code Resources in Spring Framework - CVE-2026-59283
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to improper control of dynamically-managed code resources in Spring Expression Language (SpEL) expression evaluation when evaluating expressions using SimpleEvaluationContext with the SpEL expression compiler active. A remote attacker can supply specially crafted expressions to disclose sensitive information and cause a denial of service.
The issue occurs only when expressions are evaluated with SimpleEvaluationContext and expression compilation is enabled through compiler mode settings such as IMMEDIATE or MIXED.
Affected software
Library Support for Spring
How to mitigate CVE-2026-59283
Library Support for Spring - update to 3.5.19