A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space.
Older, unsupported versions are also affected.
Older, unsupported versions are also affected.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware spring Framework |
|
| Vendors & Products |
Vmware
Vmware spring Framework |
Wed, 29 Apr 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected. | |
| Title | Spring Framework DoS with Multipart Temp Files in WebFlux | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-04-29T11:58:39.725Z
Reserved: 2026-01-09T06:54:49.675Z
Link: CVE-2026-22740
No data.
Status : Received
Published: 2026-04-29T12:16:18.333
Modified: 2026-04-29T12:16:18.333
Link: CVE-2026-22740
No data.
OpenCVE Enrichment
Updated: 2026-04-29T12:30:10Z
Weaknesses