SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-47890

CRITICAL · CVSS 9.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Spring MVC and WebFlux applications are susceptible to stream corruption when utilizing Server-Sent Events (SSE) in conjunction with view fragments, potentially leading to data integrity issues. Organizations using Spring Framework versions 6.2.0 to 6.2.19 and 7.0.0 to 7.0.8 should prioritize this vulnerability to mitigate risks associated with data corruption and ensure reliable application performance.

CVE
CVE-2026-47890
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%

Original NVD Description

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

Related CVEs

Other vulnerabilities affecting the same vendor(s)