Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
5.3.0 (custom) before 5.3.49
affected
Description
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.
Problem types
CWE-190: Integer Overflow or Wraparound
Product status
5.3.0 (custom) before 5.3.49
References
spring.io/security/cve-2026-41849