Impact
Spring Framework applications that render view fragments into Server‑Sent Events streams can suffer stream corruption. The flaw allows fragments to merge into the continuous flow, potentially altering or destroying intended content. This compromises the integrity of SSE messages sent to clients.
Affected Systems
Affected vendors include Spring; specifically the Spring Framework. The vulnerable releases are Spring Framework 7.0.0 through 7.0.8 and Spring Framework 6.2.0 through 6.2.19.
Risk and Exploitability
No CVSS or EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The flaw is exploitable by any trusted SSE endpoint that renders view fragments. In the absence of quantitative risk metrics, the threat should be treated as medium‑to‑high until a patch is applied.
OpenCVE Enrichment