CVE-2026-22735Disclosure(vmware / spring_framework)

LOWCVSS 2.6 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vmware spring_framework systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-667

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_framework

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
spring_framework

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-20: 3Mentions · 2026-05-15: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-20: 3Technical Details · 2026-05-15: 103-2005-15
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-203
Disclosure1General1Patch1
2026-05-151
Disclosure1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    Researchers found two flaws in Spring Framework (CVE-2026-22737 & CVE-2026-22735) allowing path bypasses and stream corruption. Patch your apps today. #SpringFramework #JavaSecurity #CVE #CyberSecurity #InfoSec #Vulnerability #AppSec #SpringMVC #PatchAlert https://securityonline.info/spring-framework-vulnerabilities-path-bypass-sse-corruption-cve-2026-22737/ https://t.co/FAfMGd3iR1

    Post summary

    Researchers uncovered path bypass and stream corruption flaws in Spring Framework (CVE‑2026‑22737 & CVE‑2026‑22735) and urged developers to patch their applications immediately.

    01092406
    10.7K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-22735 | Vmware Spring Foundation up to 5.3.46/6.1.25/6.2.16/7.0.5 locking (Nessus ID 303245 / WID-SEC-2026-0796) https://ift.tt/zmB5fZM A vulnerability, which was classified as problematic, has been found in Vmware Spring Foundation up to 5.3.46/6.1.25/6.2.16/7.0.5. I…

    Post summary

    A new vulnerability, CVE-2026-22735, affecting certain VMWare Spring Foundation versions has been identified and publicly disclosed, but no exploitable code, active use, or mitigation is discussed.

    0000045
    974 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22735 Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through … https://www.cve.org/CVERecord?id=CVE-2026-22735

    Post summary

    The post announces CVE-2026-22735, stating it causes stream corruption in Spring MVC/WebFlux applications using SSE for versions 7.0.0 and above, but provides no PoC, exploit, or patch details.

    00000100
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-22735 - Server Sent Event stream corruption Intel Report: https://ift.tt/T0keEAp

    Post summary

    The tweet alerts to CVE‑2026‑22735, highlighting a Server Sent Event stream corruption issue, but does not provide evidence of exploitation, PoC, fix, or false‑positive claims.

    0000036
    334 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_framework---

Explore more