VYPR
Low severity2.6NVD Advisory· Published Mar 20, 2026· Updated Apr 23, 2026

CVE-2026-22735

CVE-2026-22735

Description

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.springframework:spring-webmvcMaven
>= 7.0.0-M1, < 7.0.67.0.6
org.springframework:spring-webmvcMaven
>= 6.2.0, < 6.2.176.2.17
org.springframework:spring-webmvcMaven
>= 6.0.0, <= 6.1.21
org.springframework:spring-webmvcMaven
>= 5.3.0, <= 5.3.39
org.springframework:spring-webfluxMaven
>= 7.0.0-M1, < 7.0.67.0.6
org.springframework:spring-webfluxMaven
>= 6.2.0, < 6.2.176.2.17
org.springframework:spring-webfluxMaven
>= 6.0.0, <= 6.1.21
org.springframework:spring-webfluxMaven
>= 5.3.0, <= 5.3.39

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.