SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-47891

CRITICAL · CVSS 9.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A vulnerability exists in Spring WebFlux applications utilizing the Aalto XML processor, where the maxInMemorySize limit is not properly enforced, potentially allowing for excessive memory consumption through XML parsing. This can lead to denial-of-service conditions, impacting application availability. Organizations using affected versions of the Spring Framework should prioritize remediation to mitigate the risk of resource exhaustion attacks.

CVE
CVE-2026-47891
Severity
CRITICAL
CVSS
9.8
EPSS
0.29%

Original NVD Description

A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)