Feed/CVE-2026-41849
CVE-2026-41849HIGHCVSS 7.5

Spring Framework Denial of Service via Integer Overflow in SpEL Expressions

Published Jun 9, 2026·Updated Jul 30, 2026

NVD Description

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

Affected Packages (1)

org.springframework:spring-expressionMAVEN
Fixed in = 5.3.39

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free