Home

Description

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

PUBLISHED Reserved 2026-01-09 | Published 2026-04-29 | Updated 2026-04-29 | Assigner vmware




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-400 Uncontrolled Resource Consumption

Product status

Default status
affected

7.0.0 (semver) before 7.0.7
affected

6.2.0 (semver) before 6.2.18
affected

6.1.0 (semver) before 6.1.27
affected

5.3.0 (semver) before 5.3.48
affected

References

spring.io/security/cve-2026-22740

nvd.nist.gov/...N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&version=3.1

cve.org (CVE-2026-22740)

nvd.nist.gov (CVE-2026-22740)

Download JSON