GHSA-9cmq-m9j5-mvww
GitHub Security Advisory
Spring Framework vulnerable to Denial of Service
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Older, unsupported versions are also affected.
Specifically, an application is vulnerable when the following is true:
* The application evaluates user-supplied SpEL expressions.
Affected Packages
Maven
org.springframework:spring-expression
Affected versions:
0
(fixed in 5.3.39)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 18, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.