Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-41842PATCHED
vmware · spring_framework

Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

Description

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Affected Products

VendorProductVersions
vmwarespring_frameworkmaven/org.springframework:spring-webmvc: >= 7.0.0, <= 7.0.7, maven/org.springframework:spring-webflux: >= 7.0.0, <= 7.0.7, maven/org.springframework:spring-webmvc: >= 6.2.0, <= 6.2.18, maven/org.springframework:spring-webflux: >= 6.2.0, <= 6.2.18, maven/org.springframework:spring-webmvc: >= 6.1.0, <= 6.1.21, maven/org.springframework:spring-webflux: >= 6.1.0, <= 6.1.21, maven/org.springframework:spring-webmvc: <= 5.3.39, maven/org.springframework:spring-webflux: <= 5.3.39

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
atlassiancruciblecert_advisory90%
atlassianbitbucketcert_advisory90%
atlassianbamboocert_advisory90%
atlassianconfluencecert_advisory90%
atlassianjiracert_advisory90%

References

  • https://spring.io/security/cve-2026-41842

Related News (6 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR24d ago
Multiples vulnérabilités dans les produits IBM (31 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR31d ago
Multiples vulnérabilités dans les produits IBM (24 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories75d ago
[NEU] [hoch] VMware Tanzu Spring Framework: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB76d ago
CVE-2026-41842 | Vmware Spring Framework up to 5.3.48/6.1.27/6.2.18/7.0.7 resource consumption
→ No new info (linked only)
Tier B
CERT-FR76d ago
Multiples vulnérabilités dans les produits Spring (09 juin 2026)
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
org.springframework:spring-webmvc@7.0.8org.springframework:spring-webflux@7.0.8org.springframework:spring-webmvc@6.2.19org.springframework:spring-webflux@6.2.19
CWECWE-400
PublishedJun 9, 2026
Last enriched76d agov2
Trending Score31
Source articles6
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59310EXPKEV
vCenter directory-traversal vulnerability
Trending: 81
HIGHCVE-2026-41850EXP
Spring Framework Algorithmic Denial of Service via SpEL Expressions
Trending: 36
MEDIUMCVE-2026-41851EXP
Spring Framework Denial of Service via Unbounded Cache in SpEL
Trending: 34
MEDIUMCVE-2026-59323
Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability
Trending: 22
MEDIUMCVE-2026-59296
Micrometer StatsD and Logging meter registries line-protocol and log injection vulnerability
Trending: 15

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: description
Jun 9, 2026
Patch Available
Jun 27, 2026

Version History

v2
Last enriched 76d ago
v2Tier C76d ago

Updated vendor to Vmware, changed exploit availability to false, and provided a new description with additional details.

description
via VulDB
v176d ago

Initial creation