Executive brief
Spring Retry is a library used by developers to automatically re-attempt failed operations, such as connecting to a database or calling an external service. A vulnerability in how it handles 'stateful' retries allows an attacker to send many unique, failing requests that fill up the application's internal memory cache. Once this cache is full, the application will stop processing new retries and circuit breakers, potentially leading to a complete service outage or degraded performance.
Technical details
A resource exhaustion vulnerability exists in Spring Retry's RetryContextCache. The component allocates resources for stateful retries without sufficient throttling or eviction policies for unique requests. An unauthenticated remote attacker can exploit this by crafting a high volume of unique requests that trigger failures, filling the application-wide cache to its capacity. Once the limit is reached, the cache permanently rejects updates, causing subsequent stateful retries and circuit breaker mechanisms to fail. The issue is addressed in version 2.0.13 by implementing LRU (Least Recently Used) eviction and improved cache management.
Affected products
- Spring Spring Retry 2.0.0 through 2.0.12; 1.3.0 through 1.3.4
Timeline
- 2026-06-04: other: Issue reported on GitHub
- 2026-06-09: disclosed: NVD and GitHub Advisory published
- 2026-06-09: advisory
- 2026-07-29: patched: Advisory updated with patch information