CVE-2026-47891 affects Spring WebFlux applications that use the Aalto XML processor for XML input parsing. The vulnerability stems from the application failing to correctly enforce the maxInMemorySize limit, which could allow attackers to cause excessive memory consumption. The issue spans a wide range of Spring Framework versions including 5.2.x through 7.0.x. Affected versions include Spring Framework 5.2.25.RELEASE and earlier, 5.3.0-5.3.49, 6.0.0-6.0.30, 6.1.0-6.1.28, 6.2.0-6.2.19, and 7.0.0-7.0.8. This vulnerability is classified as high severity and was published via NVD (nvd.nist.gov). Users are advised to review the Spring Security advisory and upgrade to patched versions.