Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-41850EXPLOITEDPATCHED
vmware · spring_framework

Spring Framework Algorithmic Denial of Service via SpEL Expressions

Description

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Affected Products

VendorProductVersions
vmwarespring_frameworkmaven/org.springframework:spring-expression: >= 7.0.0, <= 7.0.7, maven/org.springframework:spring-expression: >= 6.2.0, <= 6.2.18, maven/org.springframework:spring-expression: >= 6.1.0, <= 6.1.21, maven/org.springframework:spring-expression: <= 5.3.39

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
atlassianbamboocert_advisory90%
atlassianconfluencecert_advisory90%
atlassianfisheyecert_advisory90%
atlassianjiracert_advisory90%
atlassiancruciblecert_advisory90%

References

  • https://spring.io/security/cve-2026-41850

Related News (5 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR24d ago
Multiples vulnérabilités dans les produits IBM (31 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR31d ago
Multiples vulnérabilités dans les produits IBM (24 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories75d ago
[NEU] [hoch] VMware Tanzu Spring Framework: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB76d ago
CVE-2026-41850 | Vmware Spring Framework up to 5.3.48/6.1.27/6.2.18/7.0.7 Spring Expression Language algorithmic complexity
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
org.springframework:spring-expression@7.0.8org.springframework:spring-expression@6.2.19
CWECWE-407
PublishedJun 9, 2026
Last enriched76d agov2
Trending Score36
Source articles5
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59310EXPKEV
vCenter directory-traversal vulnerability
Trending: 81
MEDIUMCVE-2026-41851EXP
Spring Framework Denial of Service via Unbounded Cache in SpEL
Trending: 34
HIGHCVE-2026-41842
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Trending: 31
MEDIUMCVE-2026-59323
Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability
Trending: 22
MEDIUMCVE-2026-59296
Micrometer StatsD and Logging meter registries line-protocol and log injection vulnerability
Trending: 15

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: description, activelyExploited
Jun 9, 2026
Actively Exploited
Jun 27, 2026
Patch Available
Jun 27, 2026

Version History

v2
Last enriched 76d ago
v2Tier C76d ago

Updated vendor to VMware, changed exploit availability to false, and added new description with details about the vulnerability.

descriptionactivelyExploited
via VulDB
v176d ago

Initial creation