---
id: CVE-2026-47890
aliases:
  - GHSA-j9f9-w8pj-32f8
title: Spring Framework Server Sent Event stream corruption while rendering fragments
summary: Spring Framework Server Sent Event stream corruption while rendering fragments
severity: critical
cvss: 9.8
cwe:
  - CWE-93
vendor: springframework
product: 'org.springframework:spring-webflux'
ecosystem: maven
affected:
  - 'org.springframework:spring-webflux >= 6.2.0, <= 6.2.19'
  - 'org.springframework:spring-webflux >= 7.0.0, <= 7.0.8'
  - 'org.springframework:spring-webmvc >= 6.2.0, <= 6.2.19'
  - 'org.springframework:spring-webmvc >= 7.0.0, <= 7.0.8'
patched:
  - 'org.springframework:spring-webflux 7.0.9'
  - 'org.springframework:spring-webmvc 7.0.9'
published: '2026-08-27'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T13:20:36Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-j9f9-w8pj-32f8'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47890'
  - url: 'https://spring.io/security/cve-2026-47890'
  - url: 'https://github.com/advisories/GHSA-j9f9-w8pj-32f8'
tags:
  - ghsa
  - maven
epss: 0.00564
epssPercentile: 0.45026
ingestedAt: '2026-10-07T13:31:04.600Z'
---

## Overview

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19

## Affected packages

- `org.springframework:spring-webflux >= 6.2.0, <= 6.2.19`
- `org.springframework:spring-webflux >= 7.0.0, <= 7.0.8`
- `org.springframework:spring-webmvc >= 6.2.0, <= 6.2.19`
- `org.springframework:spring-webmvc >= 7.0.0, <= 7.0.8`

## Remediation

Upgrade to a patched release:

- `org.springframework:spring-webflux 7.0.9`
- `org.springframework:spring-webmvc 7.0.9`
