CVE-2026-22740
Spring Framework DoS with Multipart Temp Files in WebFlux
6.5
MEDIUM
CVSS 3.1
EPSS 0.34%
描述
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.
如何修補 CVE-2026-22740
要修補 CVE-2026-22740,請將受影響套件升級到下列已修補版本。
- —升級至 7.0.7 或更新版本
CVE-2026-22740 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 7.0.0, < 7.0.7
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |