CVE-2026-41850: Spring Framework Algorithmic Denial of Service via SpEL Expressions
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41850?
CVE-2026-41850 has a severity rating of high, with a CVSS score of 7.5.
How do I fix CVE-2026-41850?
To fix CVE-2026-41850, ensure you update to the latest version of the VMware Spring Framework that addresses this vulnerability.
What type of attack does CVE-2026-41850 involve?
CVE-2026-41850 involves an Algorithmic Denial of Service (DoS) attack that exploits SpEL expression evaluation.
Who is affected by CVE-2026-41850?
Applications that utilize user-supplied Spring Expression Language (SpEL) expressions are affected by CVE-2026-41850.
What are the potential consequences of CVE-2026-41850?
The potential consequences of CVE-2026-41850 include excessive resource consumption leading to application degradation or downtime.