9.8

CVE-2026-59313

Server Sent Event stream corruption in Spring MVC functional web framework

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE).
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Framework Version >= 5.3.0 <= 5.3.49
VMware ≫ Spring Framework Version >= 6.0.0 <= 6.0.30
VMware ≫ Spring Framework Version >= 6.1.0 <= 6.1.28
VMware ≫ Spring Framework Version >= 6.2.0 <= 6.2.19
VMware ≫ Spring Framework Version >= 7.0.0 <= 7.0.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.316
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.