Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.
Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-83f7-v6px-pp3h | Spring Framework Denial of Service via Multipart Requests in WebFlux |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-41840 |
|
Wed, 12 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Spring WebFlux Denial of Service via Multipart Requests |
Sat, 20 Jun 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Spring Framework Denial of Service via Multipart Requests in WebFlux |
Sat, 20 Jun 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48. |
| Weaknesses | CWE-401 |
Tue, 09 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware spring Framework |
|
| CPEs | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vmware
Vmware spring Framework |
Tue, 09 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Framework |
|
| Vendors & Products |
Spring
Spring spring Framework |
Tue, 09 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | |
| Title | Spring Framework Denial of Service via Multipart Requests in WebFlux | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-20T00:11:52.160Z
Reserved: 2026-04-22T06:22:01.123Z
Link: CVE-2026-41840
Updated: 2026-06-09T13:31:08.172Z
Status : Analyzed
Published: 2026-06-09T05:16:35.967
Modified: 2026-07-23T08:10:00.137
Link: CVE-2026-41840
No data.
OpenCVE Enrichment
Updated: 2026-08-12T01:45:04Z
Github GHSA