PT-2026-82718 · Vmware · Spring Framework

CVE-2026-59314

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Spring Framework versions 7.0.0 through 7.0.8 Spring Framework versions 6.2.0 through 6.2.19 Spring Framework versions 6.1.0 through 6.1.28 Spring Framework versions 6.0.0 through 6.0.30 Spring Framework versions 5.3.0 through 5.3.49 Spring Framework versions prior to 5.2.25.RELEASE
Description Applications that construct a Content-Disposition header value using untrusted input are susceptible to HTTP response splitting. This occurs when a malicious file name is provided as input, allowing an attacker to split the HTTP response into multiple responses.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59314

Affected Products

Spring Framework