SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47885

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The PartEventHttpMessageReader in Spring WebFlux is vulnerable due to a failure to enforce the maxPartSize limit when the maxInMemorySize is set to -1, potentially allowing for excessive memory consumption through large multipart requests. This could lead to denial-of-service conditions, impacting application availability. Organizations using affected versions of the Spring Framework (6.1.x, 6.2.x, or 7.0.x) should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-47885
Severity
HIGH
CVSS
7.5
EPSS
0.26%

Original NVD Description

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

Related CVEs

Other vulnerabilities affecting the same vendor(s)