Synopsis
The Spring Framework install on the remote host is affected by multiple vulnerabilities.
Description
The version of Spring Framework installed on the remote host is prior to 5.2.26, 5.3.x prior to 5.3.50, 6.0.x prior to 6.0.31, 6.1.x prior to 6.1.29, 6.2.x prior to 6.2.20, or 7.0.x prior to 7.0.8.1. It is, therefore, affected by multiple vulnerabilities:
- Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors are vulnerable to arbitrary HTML/JavaScript code injection, potentially resulting in a reflected cross-site scripting (XSS) vulnerability. (CVE-2026-59281)
- Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator is used with a BigDecimal or BigInteger operand and a large exponent value. Evaluation of such an expression can consume excessive CPU time and JVM heap memory, leading to application degradation or unavailability. (CVE-2026-47886)
- Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Under these conditions, a view name containing backslash sequences can escape the configured template directory, potentially exposing files that should not be accessible. (CVE-2026-59280)
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Upgrade to Spring Framework version 5.2.26 / 5.3.50 / 6.0.31 / 6.1.29 / 6.2.20 / 7.0.8.1 / 7.0.9 or later. Note that some fixed releases are available to Enterprise Support customers only; refer to the vendor advisory for details.
Plugin Details
File Name: spring_framework_CVE-2026-47886.nasl
Agent: windows, macosx, unix
Configuration: Enable thorough checks (optional)
Supported Sensors: Nessus Agent, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Information
CPE: cpe:/a:pivotal_software:spring_framework, cpe:/a:vmware:spring_framework
Required KB Items: installed_sw/Spring Framework
Patch Publication Date: 8/20/2026
Vulnerability Publication Date: 8/20/2026