Home
MEDIUM: 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
7.0.0 (custom) before 7.0.8
affected
6.2.0 (custom) before 6.2.19
affected
6.1.0 (custom) before 6.1.28
affected
5.3.0 (custom) before 5.3.49
affected
Description
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Problem types
CWE-524: Use of Cache-Containing Sensitive Information to Aid in Security Bypass
Product status
7.0.0 (custom) before 7.0.8
6.2.0 (custom) before 6.2.19
6.1.0 (custom) before 6.1.28
5.3.0 (custom) before 5.3.49
References
spring.io/security/cve-2026-41841