CVE-2026-47885

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28
References
Link Resource
https://spring.io/security/cve-2026-47885 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-27 06:17

Updated : 2026-09-10 14:06


NVD link : CVE-2026-47885

Mitre link : CVE-2026-47885

CVE.ORG link : CVE-2026-47885


JSON object : View

Products Affected

vmware

  • spring_framework
CWE
CWE-770

Allocation of Resources Without Limits or Throttling