Loading HuntDB...

GHSA-9cmq-m9j5-mvww

GitHub Security Advisory

Spring Framework vulnerable to Denial of Service

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Older, unsupported versions are also affected.

Specifically, an application is vulnerable when the following is true:

* The application evaluates user-supplied SpEL expressions.

Affected Packages

Maven org.springframework:spring-expression
Affected versions: 0 (fixed in 5.3.39)

Related CVEs

Key Information

GHSA ID
GHSA-9cmq-m9j5-mvww
Published
August 20, 2024 9:30 AM
Last Modified
June 18, 2025 5:46 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.springframework:spring-expression
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 18, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.