CVE-2026-41851
ADVISORY - githubSummary
Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Common Weakness Enumeration (CWE)
Allocation of Resources Without Limits or Throttling
Allocation of Resources Without Limits or Throttling
NIST
3.9
CVSS SCORE
5.3mediumGitHub
3.9
CVSS SCORE
5.3mediumDebian
-
CVSS SCORE
N/AlowUbuntu
3.9
CVSS SCORE
7.5mediumChainguard
CGA-jpc4-j86m-h64j
-
minimos
MINI-287h-jp76-9j59
-
minimos
MINI-3x3v-2gf6-fjw4
-
minimos
MINI-44h3-c572-rx6j
-
minimos
MINI-4h64-wxh5-pr9h
-
minimos
MINI-73c9-3hxm-rw7f
-
minimos
MINI-77f7-68w3-3q6v
-
minimos
MINI-8c3r-m69h-98cq
-
minimos
MINI-g9m7-2w3g-733h
-
minimos
MINI-h78p-jw3f-r2cc
-
minimos
MINI-hg8g-63w9-fcgc
-
minimos
MINI-jm4m-x3xx-c28w
-
minimos
MINI-qgmm-q8q7-xw6v
-
minimos
MINI-qrxr-hv6p-fhv3
-
minimos
MINI-rhr3-hc7m-qjp6
-
minimos
MINI-v758-h68p-jq7r
-
minimos
MINI-vc4c-77pf-3v5h
-
minimos
MINI-vm36-f885-3q9r
-
minimos
MINI-wmhw-8mqw-jf93
-
minimos
MINI-wr8f-98jq-65gw
-
minimos
MINI-xvrw-cw57-7xxr
-