CVE-2026-41850
ADVISORY - githubSummary
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Common Weakness Enumeration (CWE)
Inefficient Algorithmic Complexity
Inefficient Algorithmic Complexity
NIST
3.9
CVSS SCORE
7.5highGitHub
3.9
CVSS SCORE
7.5highDebian
-
CVSS SCORE
N/AlowUbuntu
-
CVSS SCORE
N/AmediumChainguard
CGA-h6qc-rp68-hhx2
-
minimos
MINI-37r5-jw59-vwq6
-
minimos
MINI-3m5m-6j7c-654f
-
minimos
MINI-3qgj-w3mv-hrj9
-
minimos
MINI-3rrx-mr6g-pw4h
-
minimos
MINI-46x2-x7vc-j5qj
-
minimos
MINI-52mr-28hj-rxfp
-
minimos
MINI-5jrc-jhw3-qfv8
-
minimos
MINI-5xx8-c42m-r4c3
-
minimos
MINI-6wcc-5448-3p7h
-
minimos
MINI-7rjx-jmmh-v84m
-
minimos
MINI-fqg4-wfrw-r259
-
minimos
MINI-g6f6-q28v-p3wr
-
minimos
MINI-jhfr-8pvv-r68g
-
minimos
MINI-jvqr-5254-pxjh
-
minimos
MINI-pg3h-qg6p-jcq9
-
minimos
MINI-qc3g-7m93-xqv4
-
minimos
MINI-vhp5-qx4w-grgj
-
minimos
MINI-vvhw-8p98-5h9v
-
minimos
MINI-wwm9-8fm3-7g4w
-
minimos
MINI-xr2j-jh3j-phwm
-