Security Advisory

CVE-2026-41849

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-09 03:51:17
Last updated 2026-06-09 13:33:03
Assigner vmware
CVSS score not scored
State PUBLISHED

Description

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.