Feed/CVE-2026-41840
CVE-2026-41840MEDIUMCVSS 5.9

Spring Framework Denial of Service via Multipart Requests in WebFlux

Published Jun 9, 2026·Updated Jul 30, 2026

NVD Description

Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Affected Packages (1)

org.springframework:spring-webfluxMAVEN
From 7.0.0
Fixed in = 7.0.7

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free