Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
| Vendor | Product | Versions |
|---|---|---|
| vmware | spring_framework | maven/org.springframework:spring-expression: >= 7.0.0, <= 7.0.7, maven/org.springframework:spring-expression: >= 6.2.0, <= 6.2.18, maven/org.springframework:spring-expression: >= 6.1.0, <= 6.1.21, maven/org.springframework:spring-expression: <= 5.3.39 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| maven | org.springframework:spring-expression | GHSA | 85% |
| vmware tanzu | spring framework | cert_advisory | 90% |
Updated vendor to VMware, changed exploit availability to false, and added new description with details about the vulnerability.
Initial creation