CVE-2026-41849

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.
References
Link Resource
https://spring.io/security/cve-2026-41849 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de desbordamiento de entero existe en la lógica de evaluación de Spring Expression Language (SpEL). Un atacante puede explotar esto al proporcionar una expresión SpEL especialmente diseñada que desencadena un consumo excesivo de recursos, lo que resulta en una denegación de servicio (DoS). Versiones afectadas: Spring Framework 5.3.0 hasta 5.3.48.

09 Jun 2026, 20:36

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
References () https://spring.io/security/cve-2026-41849 - () https://spring.io/security/cve-2026-41849 - Vendor Advisory
First Time Vmware
Vmware spring Framework

09 Jun 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 05:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-41849

Mitre link : CVE-2026-41849

CVE.ORG link : CVE-2026-41849


JSON object : View

Products Affected

vmware

  • spring_framework
CWE
CWE-190

Integer Overflow or Wraparound