PatchSiren cyber security CVE debrief
CVE-2026-41841 Spring CVE debrief
A medium-severity vulnerability, CVE-2026-41841, was found in Spring MVC and WebFlux applications. This issue allows for Information Disclosure attacks when resolving static resources. The vulnerability affects multiple versions of the Spring Framework, including 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.
- Vendor
- Spring
- Product
- Spring Framework
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-09
- Original CVE updated
- 2026-07-17
- Advisory published
- 2026-06-09
- Advisory updated
- 2026-07-17
Who should care
Users of affected Spring Framework versions should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The vulnerability has a CVSS score of 5.9 and is classified as CWE-524. It can be exploited through a network attack (AV:N) with high complexity (AC:H) and no privileges required (PR:N). The attack can lead to high confidentiality impact (C:H) with no integrity (I:N) or availability (A:N) impact.
Defensive priority
MEDIUM
Recommended defensive actions
- Upgrade to a non-vulnerable version of the Spring Framework.
- Refer to the vendor advisory for more information and mitigation steps: [ref-4]
Evidence notes
The CVE record [cve-org] and NVD detail [nvd] provide additional information about the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-41841 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-41841
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-41841 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41841
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://spring.io/security/cve-2026-41841
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.