← Back to overview

A vulnerability has been identified in Spring MVC and WebFlux applications affecting Server-Sent Events (SSE) when used with view fragments. The flaw can lead to stream corruption, potentially impacting data integrity and application reliability. Affected versions include Spring Framework 7.0.0 through 7.0.8 and Spring Framework 6.2.0 through 6.2.19. The vulnerability is tracked as CVE-2026-47890 and has been published by NVD. Organizations using the affected Spring Framework versions should review their SSE implementations. The issue affects both the reactive (WebFlux) and traditional (MVC) web stacks within the Spring ecosystem. Patches or mitigations are expected to be available through official Spring security advisories. The criticality has been assessed as High given the breadth of affected versions and widespread use of the Spring Framework in enterprise applications.

Affected products

  • Spring Framework 6.2.0 - 6.2.19
  • Spring Framework 7.0.0 - 7.0.8
  • Spring MVC
  • Spring WebFlux

Related CVE's

  • CVE-2026-47890

Categories

  • Enterprise Applications
  • Web Technologies