Junglewise Threat Intelligence

CVE-2026-59313: Spring Framework stream corruption in Server-Sent Events

CVE-2026-59313 · Severity: critical · CVSS 9.8 · Published 2026-08-27

Technologies: VMware Spring Framework. Vendors: VMware.

Executive brief

Spring Framework, a widely-used Java application framework, has a vulnerability in its functional web framework that corrupts Server-Sent Events (SSE) streams used for real-time server-to-client communication. An attacker with network access can exploit this to disrupt SSE-based features, causing data loss or service unavailability in applications that rely on this streaming capability.

Technical details

This vulnerability affects Spring Framework's functional web framework implementation when handling Server-Sent Events (SSE). The root cause involves stream corruption when processing SSE responses, which can be triggered by a network-based attacker without authentication. The vulnerability impacts multiple versions across Spring Framework 5.3, 6.0, 6.1, 6.2, and 7.0 branches. An attacker can exploit this to corrupt or disrupt SSE streams, potentially leading to message loss or application-level denial of service for real-time communication features.

Affected products

  • VMware Spring Framework 5.3.0-5.3.49, 6.0.0-6.0.30, 6.1.0-6.1.28, 6.2.0-6.2.19, 7.0.0-7.0.8

Timeline

  • 2026-08-27: disclosed: CVE-2026-59313 published

References

Related threats