Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-47890

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent…

Technology

Spring Framework

CVSS Score

9.8 / 10.0

Affected Versions

>=6.2.0 <6.2.20; >=7.0.0 <7.0.8.1

Upstream Fix

See upstream advisory

Published

August 27, 2026

OSSeva Coverage

Fixed upstream

Description

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

Is your Spring Framework deployment affected?

If you're running >=6.2.0 <6.2.20; >=7.0.0 <7.0.8.1, you need this patch. Book a discovery call to get covered.