CVE-2026-41852
ADVISORY - githubSummary
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Common Weakness Enumeration (CWE)
Incorrect Authorization
Incorrect Authorization
NIST
2.2
CVSS SCORE
3.7lowGitHub
2.2
CVSS SCORE
3.7lowDebian
-
CVSS SCORE
N/AlowUbuntu
3.9
CVSS SCORE
5.3mediumChainguard
CGA-gxpc-c44r-7wc6
-
minimos
MINI-27f5-xfqj-6q9v
-
minimos
MINI-47g3-x47q-h68h
-
minimos
MINI-5jm9-2g2v-64xw
-
minimos
MINI-6522-3vcv-8whv
-
minimos
MINI-6h44-fg92-57vq
-
minimos
MINI-79fv-v837-7vw7
-
minimos
MINI-85f9-fq5q-9cr7
-
minimos
MINI-95v5-fxxq-cwjc
-
minimos
MINI-c4gj-m3fm-5fx6
-
minimos
MINI-j986-7q5c-2c6r
-
minimos
MINI-jc5j-v86x-f9x8
-
minimos
MINI-jvrg-46rj-p8j8
-
minimos
MINI-p79q-3prr-mvx9
-
minimos
MINI-p8m2-hcxx-h8qp
-
minimos
MINI-p9g4-x7x6-4whr
-
minimos
MINI-pw8h-9rj9-r3x5
-
minimos
MINI-rw8q-9mhf-hvh9
-
minimos
MINI-v8xp-8833-97hq
-
minimos
MINI-vpff-qrcm-xqwv
-
minimos
MINI-x664-hg7r-66vg
-