HTTP Response Splitting Vulnerability in Spring Framework by Pivotal Software
CVE-2026-59314

3.7LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59314?

The Spring Framework is susceptible to HTTP response splitting due to inadequate validation of untrusted inputs used in the construction of Content-Disposition header values. This vulnerability allows attackers to exploit the application by injecting malicious file names, potentially leading to various security issues, including unauthorized content delivery and session fixation attacks. It is crucial for developers using affected versions of the Spring Framework to implement proper input validation to mitigate this threat.

Affected Version(s)

Spring Framework 7.0.0 <= 7.0.8

Spring Framework 6.2.0 <= 6.2.19

Spring Framework 6.1.0 <= 6.1.28

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.