Spring Framework Denial-of-Service Vulnerability in WebFlux Multipart Request Processing

Vulnerability

A denial-of-service vulnerability has been identified in Spring WebFlux applications that process multipart requests. This issue affects Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48. The vulnerability can be exploited by sending malicious multipart requests that leak memory, potentially leading to a denial-of-service condition in the application.

Impact

Exploitation of this vulnerability can cause memory leaks, leading to denial-of-service conditions where the application becomes unresponsive or unavailable.

Remediation

Users should upgrade to Spring Framework versions 7.0.8, 6.2.19, 6.1.28, or 5.3.49. Instructions for upgrading to these versions are available on the Spring Framework website.

Added: Jun 9, 2026, 6:29 AM
Updated: Jun 9, 2026, 6:29 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
4.7
remediation
7.7
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.