Description
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.

Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Published: 2026-06-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can craft a Spring Expression Language (SpEL) expression that causes the expression evaluator to consume excessive CPU or memory resources, resulting in a slowdown or complete unavailability of the application. This vulnerability is a classic example of CWE‑407 – Excessive Resource Consumption, and it requires only that the application accepts user‑supplied SpEL expressions for evaluation.

Affected Systems

All Spring Framework installations running Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, or 5.3.0 through 5.3.48 are affected.

Risk and Exploitability

The CVSS score of 7.5 indicates a high likelihood of causing disruption if exploited. EPSS data is not available, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting it is known but not yet actively exploited on a large scale. The attack vector is through user input that triggers SpEL evaluation, meaning the vulnerability can be exploited remotely by any client that can submit such expressions to the application.

Generated by OpenCVE AI on June 9, 2026 at 05:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Spring Framework release (Spring Framework 7.0.8 or later, 6.2.19 or later, 6.1.28 or later, 5.3.49 or later).
  • If an upgrade is not immediately possible, disable or tightly restrict the use of SpEL in the application, or validate and sanitize all user‑supplied expressions to prevent resource‑intensive operations.
  • Apply the official Spring advisory correction and monitor application performance for anomalous spikes in CPU/memory usage.

Generated by OpenCVE AI on June 9, 2026 at 05:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 09 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware spring Framework
CPEs cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
Vendors & Products Vmware
Vmware spring Framework

Tue, 09 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring Framework
Vendors & Products Spring
Spring spring Framework

Tue, 09 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Description Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Title Spring Framework Algorithmic Denial of Service via SpEL Expressions
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Spring Spring Framework
Vmware Spring Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-06-09T13:34:37.847Z

Reserved: 2026-04-22T06:22:08.200Z

Link: CVE-2026-41850

cve-icon Vulnrichment

Updated: 2026-06-09T13:34:34.941Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T05:16:37.177

Modified: 2026-06-09T20:36:09.657

Link: CVE-2026-41850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T05:45:26Z

Weaknesses