Spring Framework < 5.2.26 / 5.3.x < 5.3.50 / 6.0.x < 6.0.31 / 6.1.x < 6.1.29 / 6.2.x < 6.2.20 / 7.0.x < 7.0.8.1 Multiple Vulnerabilities

high Nessus Plugin ID 341189

Synopsis

The Spring Framework install on the remote host is affected by multiple vulnerabilities.

Description

The version of Spring Framework installed on the remote host is prior to 5.2.26, 5.3.x prior to 5.3.50, 6.0.x prior to 6.0.31, 6.1.x prior to 6.1.29, 6.2.x prior to 6.2.20, or 7.0.x prior to 7.0.8.1. It is, therefore, affected by multiple vulnerabilities:

- Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors are vulnerable to arbitrary HTML/JavaScript code injection, potentially resulting in a reflected cross-site scripting (XSS) vulnerability. (CVE-2026-59281)

- Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator is used with a BigDecimal or BigInteger operand and a large exponent value. Evaluation of such an expression can consume excessive CPU time and JVM heap memory, leading to application degradation or unavailability. (CVE-2026-47886)

- Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Under these conditions, a view name containing backslash sequences can escape the configured template directory, potentially exposing files that should not be accessible. (CVE-2026-59280)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Spring Framework version 5.2.26 / 5.3.50 / 6.0.31 / 6.1.29 / 6.2.20 / 7.0.8.1 / 7.0.9 or later. Note that some fixed releases are available to Enterprise Support customers only; refer to the vendor advisory for details.

See Also

https://spring.io/security/cve-2026-47886

https://spring.io/security/cve-2026-47887

https://spring.io/security/cve-2026-47891

https://spring.io/security/cve-2026-47893

https://spring.io/security/cve-2026-59280

https://spring.io/security/cve-2026-59281

Plugin Details

Severity: High

ID: 341189

File Name: spring_framework_CVE-2026-47886.nasl

Version: 1.2

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 8/28/2026

Updated: 8/28/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.18

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-47891

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS Score Source: CVE-2026-47891

Vulnerability Information

CPE: cpe:/a:pivotal_software:spring_framework, cpe:/a:vmware:spring_framework

Required KB Items: installed_sw/Spring Framework

Patch Publication Date: 8/20/2026

Vulnerability Publication Date: 8/20/2026

Reference Information

CVE: CVE-2026-47886, CVE-2026-47887, CVE-2026-47891, CVE-2026-47893, CVE-2026-59280, CVE-2026-59281

CWE: 209, 22, 400, 601, 770, 79

IAVA: 2026-A-0898