VYPR
Medium severity6.5NVD Advisory· Published Mar 23, 2023· Updated Jun 17, 2026

CVE-2023-20861

CVE-2023-20861

Description

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.springframework:spring-expressionMaven
>= 6.0.0, < 6.0.76.0.7
org.springframework:spring-expressionMaven
>= 5.3.0, < 5.3.265.3.26
org.springframework:spring-expressionMaven
< 5.2.23.RELEASE5.2.23.RELEASE

Affected products

2

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.