CVE-2026-22741
Received Received - Intake
Cache Poisoning in Spring MVC/WebFlux Static Resource Handling Causes DoS

Publication date: 2026-04-29

Last updated on: 2026-05-04

Assigner: VMware

Description
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring theΒ  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title Β with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-29
Last Modified
2026-05-04
Generated
2026-06-16
AI Q&A
2026-04-29
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
vmware spring_framework to 5.3.48 (exc)
vmware spring_framework From 6.1.0 (inc) to 6.1.27 (exc)
vmware spring_framework From 6.2.0 (inc) to 6.2.18 (exc)
vmware spring_framework From 7.0.0 (inc) to 7.0.7 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-524 The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Impact Analysis

This vulnerability can lead to a denial of service by breaking the front-end application for clients.

Specifically, an attacker can poison the resource cache with resources using the wrong encoding, causing the application to serve corrupted or invalid static resources.

Executive Summary

CVE-2026-22741 is a vulnerability in Spring MVC and Spring WebFlux applications related to static resource cache poisoning.

The vulnerability occurs when all of the following conditions are met: the application uses Spring MVC or Spring WebFlux; resource chain support is configured with caching enabled; encoded resource resolution is supported; and the resource cache is initially empty when an attacker gains access.

Under these circumstances, an attacker can send malicious requests that poison the resource cache with incorrectly encoded resources, which can disrupt the front-end application for clients.

Mitigation Strategies

To mitigate this vulnerability, you should upgrade your Spring Framework to a fixed version.

  • Upgrade 7.0.x versions to 7.0.7 or later (Open Source).
  • Upgrade 6.2.x versions to 6.2.18 or later (Open Source).
  • Upgrade 6.1.x versions to 6.1.27 or later (Commercial).
  • Upgrade 5.3.x versions to 5.3.48 or later (Commercial).

No additional mitigation steps are required beyond upgrading.

Compliance Impact

The provided information does not specify any direct impact of this vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.

Executive Summary

CVE-2026-22741 is a vulnerability in Spring MVC and Spring WebFlux applications related to static resource cache poisoning.

This vulnerability occurs when all the following conditions are met: the application uses Spring MVC or Spring WebFlux; resource chain support is configured with caching enabled; encoded resource resolution is supported; and the resource cache is initially empty when an attacker gains access.

Under these circumstances, an attacker can send malicious requests that poison the resource cache with incorrectly encoded resources.

This cache poisoning can cause a denial of service by disrupting the front-end application for clients.

Impact Analysis

The primary impact of this vulnerability is a denial of service (DoS) condition.

An attacker can poison the resource cache with resources using the wrong encoding, which breaks the front-end application for clients.

This disruption affects availability but does not impact confidentiality or integrity.

Mitigation Strategies

The immediate step to mitigate this vulnerability is to upgrade the Spring Framework to a fixed version.

  • Upgrade 7.0.x versions to 7.0.7 or later (Open Source).
  • Upgrade 6.2.x versions to 6.2.18 or later (Open Source).
  • Upgrade 6.1.x versions to 6.1.27 or later (Commercial).
  • Upgrade 5.3.x versions to 5.3.48 or later (Commercial).

No additional mitigation steps are required beyond upgrading.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-22741. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart