Executive brief
Spring Framework is a widely-used Java application framework for building web services and enterprise applications. The data binding feature, which automatically maps user input to object properties, contains a flaw that allows attackers to cause service disruption through denial of service attacks. Exploitation does not require authentication and can be triggered remotely, potentially impacting the availability of applications built with affected Spring versions.
Technical details
This vulnerability exists in Spring Framework's data binding infrastructure, which processes user-supplied property paths to populate target objects. An attacker can exploit this through crafted input to the data binding mechanism, causing excessive resource consumption or infinite loops that degrade or halt service availability. The vulnerability is network-accessible and does not require prior authentication or special user interaction. No patch details are explicitly provided in the advisory, but the presence of affected version ranges suggests patches are available in newer versions outside the listed ranges.
Affected products
- Spring Spring Framework 5.2.25.RELEASE and earlier, 5.3.0-5.3.49, 6.0.0-6.0.30, 6.1.0-6.1.28, 6.2.0-6.2.19, 7.0.0-7.0.8
Timeline
- 2026-08-27: disclosed