CVE-2026-22745 : Denial of service in static resource handling on Windows platforms
Summary
| CVE | CVE-2026-22745 |
|---|---|
| State | PUBLISHED |
| Assigner | vmware |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-29 12:16:18 UTC |
| Updated | 2026-05-04 14:50:16 UTC |
| Description | Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS: 0.000450000 probability, percentile 0.137830000 (date 2026-05-03)
Problem Types: CWE-400 | CWE-400 CWE-400 Uncontrolled Resource Consumption
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| 3.1 | CNA | CVSS | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
LowCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Spring Framework | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | VMware | Spring Framework | affected 7.0.0 7.0.7 OSS | Not specified |
| CNA | VMware | Spring Framework | affected 6.2.0 6.2.18 OSS | Not specified |
| CNA | VMware | Spring Framework | affected 6.1.0 6.1.27 COMMERCIAL | Not specified |
| CNA | VMware | Spring Framework | affected 5.3.0 5.3.48 COMMERCIAL | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| spring.io/security/cve-2026-22745 | [email protected] | spring.io | Vendor Advisory |
| nvd.nist.gov/vuln-metrics/cvss/v3-calculator | [email protected] | nvd.nist.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Bocheng Xiang ( @crispr ) from Fudan University. (en)
There are currently no legacy QID mappings associated with this CVE.