Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
{
"cwe_ids": [
"CWE-667"
],
"github_reviewed": true,
"severity": "LOW",
"github_reviewed_at": "2026-03-20T20:41:16Z",
"nvd_published_at": "2026-03-20T00:16:15Z"
}