LOW 3.1 Maven

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

GHSA-wg35-8jpf-2xv3 · CVE-2026-22741

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

More precisely, an application can be vulnerable when all the following are true:

When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.

Ready to move

Start Securing

Free, no credit card | First findings in minutes