PT-2023-2099 · Spring+1 · Spring Framework+1

CVE-2023-20861

·

Published

2023-03-23

·

Updated

2026-06-22

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Spring Framework versions 5.2.0.RELEASE through 5.2.22.RELEASE Spring Framework versions 5.3.0 through 5.3.25 Spring Framework versions 6.0.0 through 6.0.6
Description The issue is related to unlimited resource distribution in the Spring Framework, which can be exploited by a remote attacker using specially crafted SpEL expressions to cause a denial-of-service (DoS) condition.
Recommendations For Spring Framework versions 5.2.0.RELEASE through 5.2.22.RELEASE, update to a version outside of this range to resolve the issue. For Spring Framework versions 5.3.0 through 5.3.25, update to a version outside of this range to resolve the issue. For Spring Framework versions 6.0.0 through 6.0.6, update to a version outside of this range to resolve the issue.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01834
CLEANSTART-2026-SQ91016
CLEANSTART-2026-WK99982
CVE-2023-20861
GHSA-564R-HJ7V-MCR5
RHSA-2023:3610
RHSA-2023:3622
RHSA-2023:3771
RHSA-2024:0778

Affected Products

Debian
Spring Framework