SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47886

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Applications using the Spring Framework that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to a Denial of Service (DoS) attack when the power operator is applied to BigDecimal or BigInteger operands with large exponent values. This vulnerability can lead to resource exhaustion, potentially causing the application to become unresponsive. Organizations utilizing affected versions of the Spring Framework should prioritize patching to mitigate the risk of service disruption.

CVE
CVE-2026-47886
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)