CVE-2026-47890
N/A
N/A
Summary
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Framework | 7.0.0 <= 7.0.8 | affected |
| Spring | Spring Framework | 6.2.0 <= 6.2.19 | affected |
Weaknesses
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.