Spring MVC and WebFlux applications are vulnerable to...
Critical severity
Unreviewed
Published
Aug 27, 2026
to the GitHub Advisory Database
•
Updated Aug 27, 2026
Description
Published by the National Vulnerability Database
Aug 27, 2026
Published to the GitHub Advisory Database
Aug 27, 2026
Last updated
Aug 27, 2026
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
References