CVE Vulnerabilities

CVE-2026-41850

Inefficient Algorithmic Complexity

Published: Jun 09, 2026 | Modified: Jul 17, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.

Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Weakness

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Affected Software

NameVendorStart VersionEnd Version
Spring_frameworkVmware5.3.0 (including)5.3.49 (excluding)
Spring_frameworkVmware6.1.0 (including)6.1.28 (excluding)
Spring_frameworkVmware6.2.0 (including)6.2.18.1 (excluding)
Spring_frameworkVmware7.0.0 (including)7.0.7.1 (excluding)
Libspring-javaUbuntuquesting*

References