Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-41842PATCHED
vmware · spring_framework

Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

Description

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Affected Products

VendorProductVersions
vmwarespring_frameworkmaven/org.springframework:spring-webmvc: >= 7.0.0, <= 7.0.7, maven/org.springframework:spring-webflux: >= 7.0.0, <= 7.0.7, maven/org.springframework:spring-webmvc: >= 6.2.0, <= 6.2.18, maven/org.springframework:spring-webflux: >= 6.2.0, <= 6.2.18, maven/org.springframework:spring-webmvc: >= 6.1.0, <= 6.1.21, maven/org.springframework:spring-webflux: >= 6.1.0, <= 6.1.21, maven/org.springframework:spring-webmvc: <= 5.3.39, maven/org.springframework:spring-webflux: <= 5.3.39

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
mavenorg.springframework:spring-webfluxGHSA85%
mavenorg.springframework:spring-webmvcGHSA85%
vmware tanzuspring frameworkcert_advisory90%

References

  • https://spring.io/security/cve-2026-41842

Related News (5 articles)

Tier B
CERT-FR12d ago
Multiples vulnérabilités dans les produits IBM (31 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR19d ago
Multiples vulnérabilités dans les produits IBM (24 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories64d ago
[NEU] [hoch] VMware Tanzu Spring Framework: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB64d ago
CVE-2026-41842 | Vmware Spring Framework up to 5.3.48/6.1.27/6.2.18/7.0.7 resource consumption
→ No new info (linked only)
Tier B
CERT-FR64d ago
Multiples vulnérabilités dans les produits Spring (09 juin 2026)
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
org.springframework:spring-webmvc@7.0.8org.springframework:spring-webflux@7.0.8org.springframework:spring-webmvc@6.2.19org.springframework:spring-webflux@6.2.19
CWECWE-400
PublishedJun 9, 2026
Last enriched64d agov2
Trending Score13
Source articles5
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59310EXPKEV
vCenter directory-traversal vulnerability
Trending: 137
CRITICALCVE-2026-59309
vCenter authentication-bypass vulnerability
Trending: 17
CRITICALCVE-2026-47876
VMXNET3 out-of-bounds write vulnerability
Trending: 14
HIGHCVE-2026-41703
Out-of-bounds read vulnerability
Trending: 14
HIGHCVE-2026-41850EXP
Spring Framework Algorithmic Denial of Service via SpEL Expressions
Trending: 11

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: description
Jun 9, 2026
Patch Available
Jun 27, 2026

Version History

v2
Last enriched 64d ago
v2Tier C64d ago

Updated vendor to Vmware, changed exploit availability to false, and provided a new description with additional details.

description
via VulDB
v164d ago

Initial creation