CVE-2026-47886
N/A
N/A
Summary
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Framework | 7.0.0 <= 7.0.8 | affected |
| Spring | Spring Framework | 6.2.0 <= 6.2.19 | affected |
| Spring | Spring Framework | 6.1.0 <= 6.1.28 | affected |
| Spring | Spring Framework | 6.0.0 <= 6.0.30 | affected |
| Spring | Spring Framework | 5.3.0 <= 5.3.49 | affected |
| Spring | Spring Framework | 0 <= 5.2.25.RELEASE | affected |
Weaknesses
- CWE-400 Uncontrolled Resource Consumption
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.