Impact
A Spring WebFlux application that supports WebSocket connections may expose request headers in the exception reason when a handshake error occurs. This information disclosure flaw allows an attacker to learn values from headers such as authentication tokens or session identifiers through error messages or logs, representing a breach of confidentiality consistent with CWE‑200.
Affected Systems
Any deployment of Spring Framework versions 7.0.0‑7.0.8, 6.2.0‑6.2.19, 6.1.0‑6.1.28, 6.0.0‑6.0.30, 5.3.0‑5.3.49, and 5.2.25.RELEASE or earlier that uses Spring WebFlux with WebSocket support is vulnerable.
Risk and Exploitability
The CVSS score is not publicly available and the EPSS score is not listed, leaving the exploitation probability indeterminate. A user could trigger the flaw by sending a crafted WebSocket handshake request that causes an exception; this is the likely attack vector inferred from the description. The vulnerability is not cataloged in CISA KEV. If exploited, the attacker could obtain header data from error responses or application logs, potentially compromising authentication or session continuity.
OpenCVE Enrichment