A high-severity denial-of-service flaw, CVE-2026-41849, was disclosed in the Spring Framework SpEL evaluation engine, where an integer overflow can let a remote, unauthenticated attacker exhaust resources if a network-exposed application evaluates attacker-controlled expressions. The issue affects Spring Framework 5.3.0 through 5.3.48 and carries a CVSS 3.1 score of 7.5, with impact limited to availability.
Spring said the vulnerability applies to the 5.3.x branch and that newer releases 6.2.19 and 7.0.8 are not affected. Public open-source remediation is available in those newer branches, while the fix for 5.3.x is 5.3.49 and is available through commercial Tanzu Spring Enterprise because the 5.3 line has reached end of life; no public proof-of-concept or confirmed in-the-wild exploitation had been reported at publication time.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Spring stated that CVE-2026-41847 and CVE-2026-41849 apply to the Spring Framework 5.3.x branch, while versions 6.2.19 and 7.0.8 are not affected.
On June 8, 2026, Spring released Framework versions 6.2.19 and 7.0.8. These public OSS releases were noted as containing fixes related to CVE-2026-41849 and were stated to be unaffected by CVE-2026-41847 and CVE-2026-41849.
The Spring Framework 5.3 branch reached open-source end of life in August 2024, making later 5.3.x fixes unavailable as public OSS releases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.