Launch Week Day 1: Announcing Security Design Review
NONE 0.0 Maven

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

GHSA-wg35-8jpf-2xv3 · CVE-2026-22741

Published · Modified

Description

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

More precisely, an application can be vulnerable when all the following are true:

When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

Ready to move

Start Securing

Free, no credit card | First findings in minutes