Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-41849

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 15.7%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-41849


Contact Us

Shodan ® - All rights reserved