{"id":"CVE-2026-47886","title":"Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent…","summary":"Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-770"],"vendor":"vmware","product":"spring_framework","affected":["spring_framework < 5.2.26","spring_framework >= 5.3.0, < 5.3.50","spring_framework >= 6.0.0, < 6.0.31","spring_framework >= 6.1.0, < 6.1.29","spring_framework >= 6.2.0, < 6.2.20","spring_framework >= 7.0.0, < 7.0.8.1"],"patched":["spring_framework 7.0.8.1"],"published":"2026-08-27","updated":"2026-09-10","sourceUpdated":"2026-09-10T14:25:17.517","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47886","references":[{"url":"https://spring.io/security/cve-2026-47886","label":"security@vmware.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47886.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-47886"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2524864"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47886"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47886"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-08-27T14:59:39.970725Z"},"ingestedAt":"2026-09-13T19:08:52.455Z","epss":0.00324,"epssPercentile":0.25665,"slug":"CVE-2026-47886","body":"## Overview\n\nApplications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier\n\n## Affected\n\n- `spring_framework < 5.2.26`\n- `spring_framework >= 5.3.0, < 5.3.50`\n- `spring_framework >= 6.0.0, < 6.0.31`\n- `spring_framework >= 6.1.0, < 6.1.29`\n- `spring_framework >= 6.2.0, < 6.2.20`\n- `spring_framework >= 7.0.0, < 7.0.8.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_framework 7.0.8.1`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: OpenShift Developer Tools and Services, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat Fuse 7, Red Hat OpenShift Dev Spaces · no fix planned: OpenShift Developer Tools and Services, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat Fuse 7, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47886.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}