CVE-2026-41851: Spring Framework Denial of Service via Unbounded Cache in SpEL
Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41851?
CVE-2026-41851 has a medium severity rating of 5.3.
How do I fix CVE-2026-41851?
To mitigate CVE-2026-41851, update your Spring Framework to a version that is not affected, specifically 7.0.8 or later, 6.2.19 or later, or 6.1.14 or later.
What type of attack does CVE-2026-41851 enable?
CVE-2026-41851 enables a Denial of Service (DoS) attack due to unbounded cache growth triggered by SpEL expressions.
Which versions of the Spring Framework are affected by CVE-2026-41851?
Affected versions include Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, and 6.1.0 through 6.1.13.
What is the impact of CVE-2026-41851 on applications?
The impact of CVE-2026-41851 is that it may lead to a Denial of Service, causing affected applications to become unavailable.