n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "5.2.20"
},
{
"introduced": "5.3.0"
},
{
"fixed": "5.3.17"
}
]
}