Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
5.3
CVE-2026-41851EXPLOITEDPATCHED
vmware · spring_framework

Spring Framework Denial of Service via Unbounded Cache in SpEL

Description

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Affected Products

VendorProductVersions
vmwarespring_frameworkmaven/org.springframework:spring-expression: >= 7.0.0, <= 7.0.7, maven/org.springframework:spring-expression: >= 6.2.0, <= 6.2.18, maven/org.springframework:spring-expression: >= 6.1.0, <= 6.1.21, maven/org.springframework:spring-expression: <= 5.3.39

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
atlassianbamboocert_advisory90%
atlassianbitbucketcert_advisory90%
atlassianfisheyecert_advisory90%
atlassianconfluencecert_advisory90%
atlassiancruciblecert_advisory90%

References

  • https://spring.io/security/cve-2026-41851

Related News (5 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR24d ago
Multiples vulnérabilités dans les produits IBM (31 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR31d ago
Multiples vulnérabilités dans les produits IBM (24 juillet 2026)
→ No new info (linked only)
Tier B
BSI Advisories75d ago
[NEU] [hoch] VMware Tanzu Spring Framework: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB76d ago
CVE-2026-41851 | Vmware Spring Framework up to 5.3.48/6.1.27/6.2.18/7.0.7 Spring Expression Language allocation of resources
→ No new info (linked only)
CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
org.springframework:spring-expression@7.0.8org.springframework:spring-expression@6.2.19
CWECWE-770
PublishedJun 9, 2026
Last enriched76d agov2
Trending Score34
Source articles5
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59310EXPKEV
vCenter directory-traversal vulnerability
Trending: 81
HIGHCVE-2026-41850EXP
Spring Framework Algorithmic Denial of Service via SpEL Expressions
Trending: 36
HIGHCVE-2026-41842
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Trending: 31
MEDIUMCVE-2026-59323
Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability
Trending: 22
MEDIUMCVE-2026-59296
Micrometer StatsD and Logging meter registries line-protocol and log injection vulnerability
Trending: 15

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: description, severity, activelyExploited
Jun 9, 2026
Actively Exploited
Jun 27, 2026
Patch Available
Jun 27, 2026

Version History

v2
Last enriched 76d ago
v2Tier C76d ago

Updated vendor to VMware, changed severity to HIGH, and noted that there is no exploit available.

descriptionseverityactivelyExploited
via VulDB
v176d ago

Initial creation