Back

MEDIUM

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

Published Jun 9, 2026

Description

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.

Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Affected products

Remediation

Red Hat statement

This Moderate-impact flaw in Spring MVC and WebFlux applications allows remote, unauthenticated attackers to conduct Multipart request smuggling. This can lead to bypassing security controls or modifying data, affecting the integrity of applications utilizing these Spring Framework components.

Red Hat mitigation

Users of affected versions should upgrade to the corresponding fixed version.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Jun 9, 2026
Updated Jun 27, 2026
Reserved Apr 22, 2026
CISA Vulnrichment
Updated Jun 9, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity Moderate
Public date Jun 9, 2026
GHSA-CJPG-RGQ5-FR37