CVE-2026-22740
Spring Framework DoS with Multipart Temp Files in WebFlux
0.0
NONE
CVSS 3.1
EPSS 0.06%
Description
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.
How to fix CVE-2026-22740
To remediate CVE-2026-22740, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 7.0.7 or later
Is CVE-2026-22740 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0
- >= 7.0.0, < 7.0.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | NONE0.0 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N |