MEDIUM | APRIL 17, 2026 | CVE-2026-22740
Description
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space.
Affected Spring Products and Versions
Spring Framework:
- 7.0.0 - 7.0.6
- 6.2.0 - 6.2.17
- 6.1.0 - 6.1.26
- 5.3.0 - 5.3.47
- Older, unsupported versions are also affected.
Mitigation
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 7.0.x | 7.0.7 | OSS |
| 6.2.x | 6.2.18 | OSS |
| 6.1.x | 6.1.27 | Commercial |
| 5.3.x | 5.3.48 | Commercial |
No further mitigation steps are necessary.
Credit
This vulnerability was discovered and reported independently by Xint Code and Yuki Matsuhashi.
References
History
- 2026-04-17: Initial vulnerability report published.
Reporting a vulnerability
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy




























