MEDIUMMaven

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

CVE-2026-22741Published 4 months agoUpdated 5 days agoSource: OSV

Affected packages

  • org.springframework:spring-webflux7.0.0 → 7.0.7
  • org.springframework:spring-webmvc7.0.0 → 7.0.7

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.