Junglewise Threat Intelligence

CVE-2026-59282: Spring Framework denial of service in data binding

CVE-2026-59282 · Severity: high · CVSS 7.5 · Published 2026-08-27

Vendors: Spring.

Executive brief

Spring Framework is a widely-used Java application framework for building web services and enterprise applications. The data binding feature, which automatically maps user input to object properties, contains a flaw that allows attackers to cause service disruption through denial of service attacks. Exploitation does not require authentication and can be triggered remotely, potentially impacting the availability of applications built with affected Spring versions.

Technical details

This vulnerability exists in Spring Framework's data binding infrastructure, which processes user-supplied property paths to populate target objects. An attacker can exploit this through crafted input to the data binding mechanism, causing excessive resource consumption or infinite loops that degrade or halt service availability. The vulnerability is network-accessible and does not require prior authentication or special user interaction. No patch details are explicitly provided in the advisory, but the presence of affected version ranges suggests patches are available in newer versions outside the listed ranges.

Affected products

  • Spring Spring Framework 5.2.25.RELEASE and earlier, 5.3.0-5.3.49, 6.0.0-6.0.30, 6.1.0-6.1.28, 6.2.0-6.2.19, 7.0.0-7.0.8

Timeline

  • 2026-08-27: disclosed

References