CVE-2026-47891
N/A
N/A
Summary
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Framework | 7.0.0 <= 7.0.8 | affected |
| Spring | Spring Framework | 6.2.0 <= 6.2.19 | affected |
| Spring | Spring Framework | 6.1.0 <= 6.1.28 | affected |
| Spring | Spring Framework | 6.0.0 <= 6.0.30 | affected |
| Spring | Spring Framework | 5.3.0 <= 5.3.49 | affected |
| Spring | Spring Framework | 0 <= 5.2.25.RELEASE | affected |
Weaknesses
- CWE-770 Allocation of Resources Without Limits or Throttling
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.