PT-2026-47652 · Vmware · Spring Framework

CVE-2026-41841

·

Published

2026-06-09

·

Updated

2026-06-27

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Spring Framework versions 7.0.0 through 7.0.7 Spring Framework versions 6.2.0 through 6.2.18 Spring Framework versions 6.1.0 through 6.1.27 Spring Framework versions 5.3.0 through 5.3.48
Description Spring MVC and WebFlux applications are susceptible to information disclosure attacks during the resolution of static resources. This issue involves a cache bypass, which allows an attacker to potentially access sensitive information that should have been cached or restricted.
Recommendations Update Spring Framework versions 7.0.0 through 7.0.7 to a newer version containing the fix. Update Spring Framework versions 6.2.0 through 6.2.18 to a newer version containing the fix. Update Spring Framework versions 6.1.0 through 6.1.27 to a newer version containing the fix. Update Spring Framework versions 5.3.0 through 5.3.48 to a newer version containing the fix.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41841

Affected Products

Spring Framework