CVE-2026-41841
CVE-2026-41841 is a medium-severity vulnerability in Vmware Spring Framework with a CVSS 3.x base score of 5.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-524.
Key facts
- Severity: Medium (CVSS 3.x base score 5.9)
- EPSS exploit prediction: 0% (24th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-35328
- Weakness: CWE-524
- Affected product: Vmware Spring Framework
- Published:
- Last modified:
Description
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Frequently asked questions
- What is CVE-2026-41841?
- Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
- How severe is CVE-2026-41841?
- CVE-2026-41841 has a CVSS 3.x base score of 5.9, rated medium severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-41841 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (24th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-41841?
- CVE-2026-41841 affects Vmware Spring Framework. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-41841?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-41841 have an EU (EUVD) identifier?
- Yes. CVE-2026-41841 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-35328.
- When was CVE-2026-41841 published?
- CVE-2026-41841 was published on 2026-06-09 and last updated on 2026-07-23.
References
Affected products (1)
- cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
More vulnerabilities in Vmware Spring Framework
- CVE-2022-22965 — Critical (CVSS 9.8): A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data…
- CVE-2016-1000027 — Critical (CVSS 9.8): Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java…
- CVE-2018-1275 — Critical (CVSS 9.8): Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow…
- CVE-2018-1270 — Critical (CVSS 9.8): Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow…
- CVE-2015-5211 — Critical (CVSS 9.6): Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported…
- CVE-2018-1258 — High (CVSS 8.8): Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization…
All CVEs affecting Vmware Spring Framework →
Other CWE-524 vulnerabilities
- CVE-2026-53943 — Critical (CVSS 9.6): Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that…
- CVE-2025-64762 — Critical (CVSS 9.1): The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS &…
- CVE-2026-61836 — High (CVSS 8.6): Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching…
- CVE-2026-71316 — High (CVSS 7.5): Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries…
- CVE-2026-65755 — High (CVSS 7.5): Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere…
- CVE-2026-64792 — High (CVSS 7.5): Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs…