CVE
CVE-2026-59282
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack.Spring Framework 7.0.0 - 7.0.8Spring Framework 6.2.0 - 6.2.19Spring Framework 6.1.0 - 6.1.28Spring Framework 6.0.0 - 6.0.30Spring Framework 5.3.0 - 5.3.49Spring Framework 5.2.25.RELEASE and earlier
Package Versions Affected
Package Version
patch Availability
Automatically patch vulnerabilities without upgrading
Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request
CVSS Version
Severity
Base Score
CVSS Version
Score Vector

C
H
U
7.5
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

C
H
U
-

C
H
U
7.5
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Related Resources
No items found.