CVE-2026-22735: Server Sent Event stream corruption
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.springframework:spring-webfluxto a version that resolves this vulnerability.Fixed in 6.2.17 - Upgrade
Upgrade
maven/org.springframework:spring-webfluxto a version that resolves this vulnerability.Fixed in 7.0.6 - Upgrade
Upgrade
maven/org.springframework:spring-webmvcto a version that resolves this vulnerability.Fixed in 6.2.17 - Upgrade
Upgrade
maven/org.springframework:spring-webmvcto a version that resolves this vulnerability.Fixed in 7.0.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22735?
CVE-2026-22735 has been classified with a high severity rating due to its potential to cause stream corruption in applications.
How do I fix CVE-2026-22735?
To remediate CVE-2026-22735, you should upgrade your Spring Framework to the latest available version beyond the affected ranges.
Which versions are affected by CVE-2026-22735?
CVE-2026-22735 affects Spring Framework versions from 5.3.0 through 5.3.46, 6.1.0 through 6.1.25, 6.2.0 through 6.2.16, and 7.0.0 through 7.0.5.
What types of applications are impacted by CVE-2026-22735?
CVE-2026-22735 impacts Spring MVC and WebFlux applications that utilize Server-Sent Events.
What are the potential risks associated with CVE-2026-22735?
The potential risks of CVE-2026-22735 include data integrity issues and application instability due to stream corruption.