Back

HIGH

Spring Framework Denial of Service via AntPathMatcher

Published Jun 9, 2026

Description

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path).

Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Affected products

Remediation

Red Hat statement

A flaw was found in Spring Framework. Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then supplied to AntPathMatcher methods (match, matchStart, or extractUriTemplateVariables).

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Jun 9, 2026
Updated Jun 27, 2026
Reserved Apr 22, 2026
CISA Vulnrichment
Updated Jun 9, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity Moderate
Public date Jun 9, 2026
GHSA-659M-PX2C-25WJ