Feed/CVE-2026-22740
CVE-2026-22740MEDIUMCVSS 6.5

Spring Framework DoS with Multipart Temp Files in WebFlux

Published Apr 29, 2026·Updated Jul 2, 2026

NVD Description

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

Affected Packages (1)

org.springframework:spring-webfluxMAVEN
From 7.0.0
Fixed in = 7.0.6

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free