5.9
CVE-2026-41841
- EPSS 0.31%
- Veröffentlicht 09.06.2026 03:50:20
- Zuletzt bearbeitet 23.07.2026 08:10:00
- CVE-Watchlists
- Unerledigt
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Framework Version >= 5.3.0 < 5.3.49
VMware ≫ Spring Framework Version >= 6.1.0 < 6.1.28
VMware ≫ Spring Framework Version >= 6.2.0 < 6.2.18.1
VMware ≫ Spring Framework Version >= 7.0.0 < 7.0.7.1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.229 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| VMware | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-524 Use of Cache Containing Sensitive Information
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
https://spring.io/security/cve-2026-41841