CVE-2026-41849
ADVISORY - githubSummary
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS).
Affected versions: Spring Framework 5.3.0 through 5.3.48.
EPSS Score: 0.00263 (0.180)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Integer Overflow or Wraparound
ADVISORY - github
Integer Overflow or Wraparound
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in