VYPR
Vypr IntelligenceAI-generatedAug 27, 2026· 16 CVEs

Spring Framework: 16 Vulnerabilities Including Critical Flaws Disclosed Together

Spring Projects patched 16 critical and high-severity vulnerabilities in the Spring Framework disclosed on August 27, 2026, impacting multiple versions.

Key findings

  • 16 Spring Framework vulnerabilities disclosed on August 27, 2026, with critical and high severity flaws.
  • Critical vulnerabilities include SSE stream corruption, SpEL bypass, XML parsing limits, and SSRF/RCE via XsltView.
  • High severity issues encompass DoS via data binding, information disclosure in WebFlux, SpEL power operator DoS, and maxPartSize enforcement failure.
  • Affected versions range from Spring Framework 5.2.x to 7.0.8; patches are available.
  • The batch includes vulnerabilities related to HTTP response splitting, XSS, open redirects, and path traversal.

On August 27, 2026, Spring Projects addressed a significant batch of 16 vulnerabilities disclosed simultaneously, impacting multiple versions of the Spring Framework. These vulnerabilities, ranging in severity from medium to critical, were patched within a 14-hour window, highlighting a coordinated disclosure event by the Spring security team. The disclosures underscore the importance of timely patching for applications relying on the widely-used Java framework.

Several critical vulnerabilities were detailed in the advisories. CVE-2026-59313 and CVE-2026-47890, both rated Critical (CVSSv3 9.8), involve stream corruption when using Server-Sent Events (SSE) in Spring MVC and WebFlux applications. Additionally, CVE-2026-47891 (Critical, CVSSv3 9.8) affects WebFlux applications using the Aalto XML processor, failing to enforce maxInMemorySize limits, potentially leading to resource exhaustion. Another critical flaw, CVE-2026-47884 (Critical, CVSSv3 9.8), allows Server-Side Request Forgery (SSRF) and Remote Code Execution (RCE) in Spring MVC applications using XsltView under specific configurations.

The batch also included critical vulnerabilities related to Spring Expression Language (SpEL) and authentication bypass. CVE-2026-59283 (Critical, CVSSv3 9.1) describes a SpEL safety guard bypass when the expression compiler is active. Furthermore, CVE-2026-47892 (Critical, CVSSv3 9.8) points to a header predicate bypass in WebFlux applications with functional endpoints deployed using DispatcherServlet, affecting pre-flight requests.

High-severity issues were also prominent. CVE-2026-59282 (High, CVSSv3 7.5) involves a Denial of Service (DoS) vulnerability in Spring's data binding infrastructure when applying user-supplied property paths. CVE-2026-47893 (High, CVSSv3 7.5) highlights a potential information disclosure in Spring WebFlux WebSocket applications by including request headers in exception reasons. Another high-severity vulnerability, CVE-2026-47886 (High, CVSSv3 7.5), relates to a DoS attack via the SpEL power operator with BigDecimal or BigInteger operands and large exponents. CVE-2026-47885 (High, CVSSv3 7.5) details a PartEventHttpMessageReader in Spring WebFlux that fails to enforce maxPartSize limits when maxInMemorySize is set to -1.

Medium-severity vulnerabilities included CVE-2026-59314, which could lead to HTTP response splitting if untrusted input is used for Content-Disposition headers. CVE-2026-59281 (Medium, CVSSv3 6.1) allows arbitrary HTML/JavaScript injection in Spring MVC and WebFlux applications with specific error rendering configurations. CVE-2026-47887 (Medium, CVSSv3 6.1) presents an open redirect vulnerability in Spring MVC's UrlFileNameViewController under certain mapping conditions. CVE-2026-47883 (Medium, CVSSv3 6.1) addresses an open redirect vulnerability in UrlHandlerFilter when broadly matching patterns are used in both Spring MVC and WebFlux. Lastly, CVE-2026-59280 (Medium, CVSSv3 4.3) involves path traversal in Spring Framework's FreeMarker integration when controller view names are derived from untrusted input.

The affected versions span Spring Framework 7.0.0 through 7.0.8, 6.2.0 through 6.2.19, 6.1.0 through 6.1.28, 6.0.0 through 6.0.30, and 5.3.0 through 5.3.49, with some CVEs also affecting earlier 5.2.x releases. Spring Projects has released patches for these versions, and users are strongly advised to consult the official advisories for specific upgrade paths and mitigation strategies. This coordinated disclosure event emphasizes the need for continuous vigilance and prompt application of security updates within the Spring ecosystem.

Vypr Intelligence noted this disclosure as part of a larger batch of 25 vulnerabilities across Spring Projects on August 27, 2026. Vypr Intelligence

AI-written article. Grounded in 16 CVE records listed below.