Vulnerability GHSA-j9f9-w8pj-32f8
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
1 month ago
August 27, 2026 at 06:31 AM UTC
Spring Framework Server Sent Event stream corruption while rendering fragments
>=6.2.0 <6.2.20, >=7.0.0 <7.0.9
>=6.2.0 <6.2.20, >=7.0.0 <7.0.9
Summary
Spring Framework Server Sent Event stream corruption while rendering fragments
Details
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
1 month ago
Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints
==5.2.10.RELEASE, ==5.2.11.RELEASE, ==5.2.12.RELEASE, ==5.2.13.RELEASE, ==5.2.14.RELEASE, ==5.2.15.RELEASE, ==5.2.16.RELEASE, ==5.2.17.RELEASE, ==5.2.18.RELEASE, ==5.2.19.RELEASE, ==5.2.20.RELEASE, ==5.2.21.RELEASE, ==5.2.22.RELEASE, ==5.2.23.RELEASE, ==5.2.24.RELEASE, ==5.2.25.RELEASE, ==5.2.5.RELEASE, ==5.2.6.RELEASE, ==5.2.7.RELEASE, ==5.2.8.RELEASE, ==5.2.9.RELEASE, >=5.3.0 <5.3.40, >=6.0.0 <6.0.24, >=6.1.0 <6.1.22, >=6.2.0 <6.2.20, >=7.0.0 <7.0.9 GHSA-9qf2-26p9-2q2q
==5.2.10.RELEASE, ==5.2.11.RELEASE, ==5.2.12.RELEASE, ==5.2.13.RELEASE, ==5.2.14.RELEASE, ==5.2.15.RELEASE, ==5.2.16.RELEASE, ==5.2.17.RELEASE, ==5.2.18.RELEASE, ==5.2.19.RELEASE, ==5.2.20.RELEASE, ==5.2.21.RELEASE, ==5.2.22.RELEASE, ==5.2.23.RELEASE, ==5.2.24.RELEASE, ==5.2.25.RELEASE, ==5.2.5.RELEASE, ==5.2.6.RELEASE, ==5.2.7.RELEASE, ==5.2.8.RELEASE, ==5.2.9.RELEASE, >=5.3.0 <5.3.40, >=6.0.0 <6.0.24, >=6.1.0 <6.1.22, >=6.2.0 <6.2.20, >=7.0.0 <7.0.9 GHSA-9qf2-26p9-2q2q
Critical
1 month ago
Spring Framework Improper Path Limitation in XsltView
1.0.0 - 1.0.1 GHSA-pc63-qcmh-9cmg
1.0.0 - 1.0.1 GHSA-pc63-qcmh-9cmg
Medium Risk
4 months ago
Spring Framework Cross-site Scripting via JSP Form Tags
1.0.0 - 1.0.1 GHSA-957g-f97v-vppc
1.0.0 - 1.0.1 GHSA-957g-f97v-vppc
Medium Risk
4 months ago
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
1.0.0 - 1.0.1 GHSA-cjpg-rgq5-fr37
1.0.0 - 1.0.1 GHSA-cjpg-rgq5-fr37
Medium Risk
4 months ago
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
1.0.0 - 1.0.1 GHSA-cjpg-rgq5-fr37
1.0.0 - 1.0.1 GHSA-cjpg-rgq5-fr37
Impacted packages
Timeline
Published
1 month ago
August 27, 2026 at 06:31 AM UTC
Fixed (7.0.9)
Unknown
Unknown
Fixed (7.0.9)
Unknown
Unknown
Last Modified
3 hours ago
October 07, 2026 at 01:30 PM UTC