Security Vulnerability in Spring Framework Affecting SSE in MVC Applications
CVE-2026-59313

9.8CRITICAL

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59313?

Applications built on the Spring MVC framework are susceptible to stream corruption when implementing Server-Sent Events (SSE). This vulnerability arises in various versions of Spring Frameworks ranging from 5.3.x to 7.0.x. If exploited, this issue can lead to unexpected behavior in real-time applications that rely on SSE, potentially compromising data integrity and application stability. It is crucial for developers to assess and address this vulnerability to ensure the security of their applications.

Affected Version(s)

Spring Framework 7.0.0 <= 7.0.8

Spring Framework 6.2.0 <= 6.2.19

Spring Framework 6.1.0 <= 6.1.28

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.