Executive brief
Spring MVC and WebFlux, frameworks used to build Java web applications, are vulnerable to a cache poisoning issue when serving static files like images or scripts. An attacker can send specially crafted requests that cause the system to store and serve files with incorrect encoding. This can break the website's user interface for other visitors, effectively causing a partial service outage.
Technical details
Spring MVC and WebFlux are vulnerable to cache poisoning (CWE-524) within the static resource resolution mechanism. The vulnerability occurs when the resource chain is configured with caching enabled and support for encoded resource resolution is active. An attacker can exploit this by sending malicious requests when the resource cache is empty, forcing the application to cache resources with incorrect encoding. This results in a denial of service for the front-end application as clients receive corrupted or improperly encoded static assets. Patches are available in versions 7.0.7 and 6.2.18.
Affected products
- Spring spring-webflux >= 7.0.0, <= 7.0.6; >= 6.2.0, <= 6.2.17; >= 6.1.0, <= 6.1.26; <= 5.3.47
- Spring spring-webmvc >= 7.0.0, <= 7.0.6; >= 6.2.0, <= 6.2.17; >= 6.1.0, <= 6.1.26; <= 5.3.47
Timeline
- 2026-04-29: disclosed
- 2026-04-29: advisory
References
- https://api.github.com/users/yuki-matsuhashi
- https://github.com/yuki-matsuhashi
- https://api.github.com/users/yuki-matsuhashi/gists%7B/gist_id%7D
- https://api.github.com/users/yuki-matsuhashi/repos
- https://avatars.githubusercontent.com/u/250794953?v=4
- https://api.github.com/users/yuki-matsuhashi/events%7B/privacy%7D