Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
Published Jun 9, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.31%
Description
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected products
-
- Version 5.3.0StatusaffectedConstraints<5.3.49
- Version 6.1.0StatusaffectedConstraints<6.1.28
- Version 6.2.0StatusaffectedConstraints<6.2.18.1
- Version 7.0.0StatusaffectedConstraints<7.0.7.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Spring | Spring Framework | unaffected |
|
- ≥ 5.3.0 · < 5.3.49
- ≥ 6.1.0 · < 6.1.28
- ≥ 6.2.0 · < 6.2.18.1
- ≥ 7.0.0 · < 7.0.7.1
No data.
OpenShift Developer Tools and Services
jenkins
Fix deferred
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel8
Fix deferred
OpenShift Developer Tools and Services
ocp-tools-4/jenkins-rhel9
Fix deferred
OpenShift Developer Tools and Services
spring-web
Fix deferred
Red Hat Data Grid 8
spring-web
Fix deferred
Red Hat Enterprise Linux 7
xbean
Fix deferred
Red Hat Enterprise Linux 8
javapackages-tools:201801/xbean
Fix deferred
Red Hat Enterprise Linux 8
pki-core:10.6/resteasy
Fix deferred
Red Hat Enterprise Linux 8
pki-deps:10.6/resteasy
Fix deferred
Red Hat Enterprise Linux 9
resteasy
Fix deferred
Red Hat Enterprise Linux 9
xbean
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
spring-web
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/openvsx-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/pluginregistry-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
spring-web
Fix deferred
Red Hat Single Sign-On 7
spring-web
Fix deferred
Red Hat build of Apache Camel - HawtIO 4
spring-web
Fix deferred
Red Hat build of Apache Camel 4 for Quarkus 3
spring-web
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Fix deferred | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Fix deferred | n/a |
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Fix deferred | n/a |
| OpenShift Developer Tools and Services | spring-web | Fix deferred | n/a |
| Red Hat Data Grid 8 | spring-web | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | xbean | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | javapackages-tools:201801/xbean | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | resteasy | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | xbean | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-web | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | spring-web | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | spring-web | Fix deferred | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | spring-web | Fix deferred | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | spring-web | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate-impact flaw in Spring MVC and WebFlux applications allows remote, unauthenticated attackers to conduct Multipart request smuggling. This can lead to bypassing security controls or modifying data, affecting the integrity of applications utilizing these Spring Framework components.
Red Hat mitigation
Users of affected versions should upgrade to the corresponding fixed version.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jun 9, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jun–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.31% (0.00310) | 21.59th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.19% (0.00186) | 8.29th | v5 (v2026.06.15) |
| Jun 9, 2026 | 0.03% (0.00029) | 8.69th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/security/cve/CVE-2026-41853 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2486708 Issue Tracking
- https://github.com/advisories/GHSA-cjpg-rgq5-fr37 Advisory
- https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19
- https://github.com/spring-projects/spring-framework/releases/tag/v7.0.8
- https://nvd.nist.gov/vuln/detail/CVE-2026-41853
- https://spring.io/security/cve-2026-41853 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-41853
Change history (0)
No recorded changes yet.