GHSA-r5w3-xv2f-j59q
HIGHCVE-2026-41850Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability.
- Affected
- >= 7.0.0, <= 7.0.7
- Fixed in
- 7.0.8
- Weakness
- CWE-407
- Published
- 2026-06-09
- Source
- github