CVE-2026-47890Critical· 9.8▾ MidnightSpring Framework Server Sent Event stream corruption while rendering fragments
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.6%
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
org.springframework:spring-webflux >= 6.2.0, <= 6.2.19org.springframework:spring-webflux >= 7.0.0, <= 7.0.8org.springframework:spring-webmvc >= 6.2.0, <= 6.2.19org.springframework:spring-webmvc >= 7.0.0, <= 7.0.8Upgrade to a patched release:
org.springframework:spring-webflux 7.0.9org.springframework:spring-webmvc 7.0.9Connected by shared product, vendor, weakness, or advisory.
CVE-2026-47892Critical· 9.8Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints
CVE-2024-38819High· 7.5Spring Framework Path Traversal vulnerability
CVE-2026-41731High· 8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
CVE-2026-41726Medium· 6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
CVE-2026-47838Medium· 6.8Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
CVE-2026-41855High· 8.1In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…