HTTP Response Splitting Vulnerability in Spring Framework by Pivotal Software
CVE-2026-59314
Currently unrated
What is CVE-2026-59314?
The Spring Framework is susceptible to HTTP response splitting due to inadequate validation of untrusted inputs used in the construction of Content-Disposition header values. This vulnerability allows attackers to exploit the application by injecting malicious file names, potentially leading to various security issues, including unauthorized content delivery and session fixation attacks. It is crucial for developers using affected versions of the Spring Framework to implement proper input validation to mitigate this threat.
Affected Version(s)
Spring Framework 7.0.0 <= 7.0.8
Spring Framework 6.2.0 <= 6.2.19
Spring Framework 6.1.0 <= 6.1.28
