CyberRota Analysis
AI-GeneratedThe PartEventHttpMessageReader in Spring WebFlux is vulnerable due to a failure to enforce the maxPartSize limit when the maxInMemorySize is set to -1, potentially allowing for excessive memory consumption through large multipart requests. This could lead to denial-of-service conditions, impacting application availability. Organizations using affected versions of the Spring Framework (6.1.x, 6.2.x, or 7.0.x) should prioritize remediation to mitigate potential exploitation risks.
Original NVD Description
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28
Related CVEs
Other vulnerabilities affecting the same vendor(s)