CVE-2026-41849
EUVD-2026-3533709.06.2026, 05:16
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vmware | spring_framework | 5.3.0 ≤ 𝑥 < 5.3.49 |
𝑥
= Vulnerable software versions
Vulnerability Media Exposure