PT-2024-7271 · Spring+1 · Spring Framework+1

·

CVE-2024-38808

·

Published

2024-08-14

·

Updated

2026-06-22

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Spring Framework versions 5.3.0 through 5.3.38 Spring Framework older unsupported versions
Description: The issue is related to the Spring Expression Language (SpEL) in Spring Framework. It is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service (DoS) condition. An application is vulnerable when it evaluates user-supplied SpEL expressions.
Recommendations: For Spring Framework versions 5.3.0 through 5.3.38, consider upgrading to a newer version to mitigate the risk. For Spring Framework older unsupported versions, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the evaluation of user-supplied SpEL expressions to minimize the risk of exploitation.

Exploit

DoS

Improper Resource Release

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08623
CLEANSTART-2026-SQ91016
CLEANSTART-2026-WK99982
CVE-2024-38808
GHSA-9CMQ-M9J5-MVWW
RHSA-2024:8884
RHSA-2024:8885
RHSA-2024:8886
RHSA-2024:8887

Affected Products

Debian
Spring Framework