CVE-2026-22745Disclosure(microsoft / spring_framework)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_framework
  • windows

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
spring_frameworkwindows

1 version affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-29: 1Mentions · 2026-05-15: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-15: 104-2905-15
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Israel@f1tym1
    Disclosure

    CVE-2026-22745 | Vmware Spring Framework up to 5.3.47/6.1.26/6.2.17/7.0.6 on Windows MVC/WebFlux resource consumption (EUVD-2026-26207 / Nessus ID 314917) https://ift.tt/BlHvYws A vulnerability described as problematic has been identified in Vmware Spring Framework up to 5.3.4…

    Post summary

    The post announces CVE‑2026‑22745 affecting various VMware Spring Framework releases, noting resource‑consumption issues on Windows MVC/WebFlux but provides no PoC, exploit, mitigation, or patch details.

    0000044
    974 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22745 Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable wh… https://www.cve.org/CVERecord?id=CVE-2026-22745

    Post summary

    The snippet reports CVE-2026‑22745 as a DoS flaw in Spring MVC/WebFlux when resolving static resources, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000102
    57.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows---
Appvmwarespring_framework---

Explore more