CVE-2026-59313: Three Spring Framework Vulnerabilities in the August Batch
This text was generated using artificial intelligence (AI).On August 20, 2026, the Spring team released a batch of 91 fixed vulnerabilities in the Spring ecosystem. Three advisories pertain to the Spring Framework:
CVE-2026-59313: Stream Corruption in Spring MVC Applications Using a Functional Web Framework and Server-Sent Events (SSE)
CVE-2026-47892: Bypassing a header predicate in certain WebFlux configurations
CVE-2026-59283: Bypassing a security check when evaluating Spring Expression Language (SpEL)
For the assessment, simply comparing the CVE numbers with the list of components is not sufficient. The Spring version in use, the functions employed, and the deployment method are also critical factors.
The advisories list several version ranges of the Spring Framework as affected. These include ranges 7.0.0 through 7.0.8, 6.2.0 through 6.2.19, 6.1.0 through 6.1.28, 6.0.0 through 6.0.30, and 5.3.0 through 5.3.49. The 5.2 series is also listed in some of the advisories.
CVE-2026-59313: Server-Sent Events in Functional Spring MVC
CVE-2026-59313 affects Spring MVC applications that use the Functional Web Framework in conjunction with Server-Sent Events. Under these conditions, stream corruption may occur. A CVSS score had not yet been assigned at the time of publication. The full Spring Advisory on CVE-2026-59313 contains further technical details.
The audit should therefore determine:
Is Spring MVC used with the functional web framework?
Do the applications use server-sent events?
Is the version of the framework being used within the affected range?
CVE-2026-47892: WebFlux and DispatcherServlet
CVE-2026-47892 affects WebFlux applications with functional endpoints if they are deployed via DispatcherServlet. During a pre-flight request, a header predicate can be bypassed. The Spring Advisory on CVE-2026-47892 classifies the vulnerability as moderate severity.
What is relevant here, then, is the specific combination of functional WebFlux endpoints, the DispatcherServlet, and pre-flight processing.
CVE-2026-59283: SpEL with an active compiler
CVE-2026-59283 affects applications that use SpEL expressions via SimpleEvaluationContext and have enabled the SpEL compiler. In this scenario, a security check can be bypassed. The Spring Advisory for CVE-2026-59283 classifies the vulnerability as moderate.
If an update cannot be applied immediately, the Spring Advisory recommends disabling SpEL compiler mode IMMEDIATE or MIXED as a temporary measure. This measure is not a substitute for an update.
Check Patch Status and Prioritization
According to the Spring advisories, updates to the next bug-fixed minor version are available, including 7.0.9 or higher, 6.2.20 or higher, 6.1.29 or higher, 6.0.31 or higher, and 5.3.50 or higher, if available. The recommended target versions can be found in the respective advisories (CVE-2026-59313, CVE-2026-47892, CVE-2026-59283).
A reliable processing sequence can be based on the following questions:
Which publicly available applications use the Spring Framework?
Which of these do SSE, functional WebFlux endpoints with DispatcherServlet, or SpEL with an active compiler use?
Which instances are included in an affected version range?
Where can an update be implemented quickly, and where are interim measures required?
For long-term planning, the list of measures specifies the migration of the no-longer-supported 5.2.x, 5.3.x, 6.0.x, and 6.1.x series to actively supported branches. In addition, a process for continuously monitoring vulnerabilities and vendor risks should be established.
The Spring Framework is widely used in the DACH region and can be found in enterprise applications across all industries. Operators of services subject to NIS 2 requirements in Germany and Austria should check whether publicly accessible Spring applications are running on affected versions and conduct a risk assessment. Swiss organizations must comply with the reporting requirements under the revised Information Security Act (ISG) to the Federal Office for Cybersecurity (BACS). If a vulnerability poses a risk to personal data, the 72-hour reporting deadline under Article 33 of the GDPR must also be observed.
Classify Externally Accessible Spring Applications
Spring applications are typically deployed as server-side web applications under their own domains. Publicly accessible services can be reached via HTTP and HTTPS. LocateRisk EASM can identify such web applications and associated assets under their own domains and provide insights into the technology used—including forgotten subdomains or unmonitored cloud instances that may not be included in the internal asset inventory.
The external view does not replace a review of the actual framework version in use or the specific functionality being utilized. However, it helps identify applicable applications to which an advisory applies, which can then be reviewed by the appropriate teams to verify their version, configuration, and patch status.
C-VRM supplements this view by providing alerts when critical vulnerabilities are discovered in technology providers' systems or when their security levels change. For this Spring Batch, the technical review of our own publicly accessible applications remains the key step.
Am I affected?
The Spring Framework versions listed above are affected. If you want to know whether the Spring Framework is even visible in your own externally accessible infrastructure, you can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-59313 is a vulnerability in the Spring Framework that affects Spring MVC applications using the functional web framework in conjunction with Server-Sent Events (SSE). Under these conditions, stream corruption may occur. A CVSS score had not yet been assigned at the time of publication.
All three vulnerabilities affect version ranges 7.0.0–7.0.8, 6.2.0–6.2.19, 6.1.0–6.1.28, 6.0.0–6.0.30, and 5.3.0–5.3.49. CVE-2026-47892 and CVE-2026-59283 also include the 5.2 series. CVE-2026-59313 does not affect the 5.2 series.
The recommended course of action is to update to a version that is not affected, as specified in the relevant Spring advisories. For CVE-2026-59283, the advisory recommends disabling SpEL compiler mode as a temporary workaround. IMMEDIATE or MIXED — However, this measure is not a substitute for a full update. No comparable workarounds have been documented for CVE-2026-59313 and CVE-2026-47892; in these cases, the update is considered the only remedy.
As of August 29, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked manufacturer advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2024-3094
Passive Assessment
Information About the CVENotes found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.