GHSA-6hcq-hmm3-jj3c

Suggest an improvement
Source
https://github.com/advisories/GHSA-6hcq-hmm3-jj3c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6hcq-hmm3-jj3c/GHSA-6hcq-hmm3-jj3c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6hcq-hmm3-jj3c
Aliases
  • CVE-2026-22735
Related
Published
2026-03-20T00:31:28Z
Modified
2026-03-26T18:29:19.981865Z
Severity
  • 2.6 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Spring MVC and WebFlux has Server Sent Event stream corruption
Details

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

Database specific
{
    "cwe_ids": [
        "CWE-667"
    ],
    "github_reviewed": true,
    "severity": "LOW",
    "github_reviewed_at": "2026-03-20T20:41:16Z",
    "nvd_published_at": "2026-03-20T00:16:15Z"
}
References

Affected packages

Maven
org.springframework:spring-webmvc

Package

Name
org.springframework:spring-webmvc
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webmvc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0-M1
Fixed
7.0.6

Affected versions

7.*
7.0.0-M1
7.0.0-M2
7.0.0-M3
7.0.0-M4
7.0.0-M5
7.0.0-M6
7.0.0-M7
7.0.0-M8
7.0.0-M9
7.0.0-RC1
7.0.0-RC2
7.0.0-RC3
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6hcq-hmm3-jj3c/GHSA-6hcq-hmm3-jj3c.json"
org.springframework:spring-webmvc

Package

Name
org.springframework:spring-webmvc
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webmvc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.2.17

Affected versions

6.*
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.2.10
6.2.11
6.2.12
6.2.13
6.2.14
6.2.15
6.2.16

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6hcq-hmm3-jj3c/GHSA-6hcq-hmm3-jj3c.json"
org.springframework:spring-webmvc

Package

Name
org.springframework:spring-webmvc
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webmvc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Last affected
6.1.21

Affected versions

6.*
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
6.0.10
6.0.11
6.0.12
6.0.13
6.0.14
6.0.15
6.0.16
6.0.17
6.0.18
6.0.19
6.0.20
6.0.21
6.0.22
6.0.23
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
6.1.9
6.1.10
6.1.11
6.1.12
6.1.13
6.1.14
6.1.15
6.1.16
6.1.17
6.1.18
6.1.19
6.1.20
6.1.21

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6hcq-hmm3-jj3c/GHSA-6hcq-hmm3-jj3c.json"
org.springframework:spring-webmvc

Package

Name
org.springframework:spring-webmvc
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webmvc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Last affected
5.3.39

Affected versions

5.*
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
5.3.10
5.3.11
5.3.12
5.3.13
5.3.14
5.3.15
5.3.16
5.3.17
5.3.18
5.3.19
5.3.20
5.3.21
5.3.22
5.3.23
5.3.24
5.3.25
5.3.26
5.3.27
5.3.28
5.3.29
5.3.30
5.3.31
5.3.32
5.3.33
5.3.34
5.3.35
5.3.36
5.3.37
5.3.38
5.3.39

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6hcq-hmm3-jj3c/GHSA-6hcq-hmm3-jj3c.json"
org.springframework:spring-webflux

Package

Name
org.springframework:spring-webflux
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webflux

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0-M1
Fixed
7.0.6

Affected versions

7.*
7.0.0-M1
7.0.0-M2
7.0.0-M3
7.0.0-M4
7.0.0-M5
7.0.0-M6
7.0.0-M7
7.0.0-M8
7.0.0-M9
7.0.0-RC1
7.0.0-RC2
7.0.0-RC3
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6hcq-hmm3-jj3c/GHSA-6hcq-hmm3-jj3c.json"
org.springframework:spring-webflux

Package

Name
org.springframework:spring-webflux
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webflux

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.2.17

Affected versions

6.*
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.2.10
6.2.11
6.2.12
6.2.13
6.2.14
6.2.15
6.2.16

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6hcq-hmm3-jj3c/GHSA-6hcq-hmm3-jj3c.json"
org.springframework:spring-webflux

Package

Name
org.springframework:spring-webflux
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webflux

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Last affected
6.1.21

Affected versions

6.*
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
6.0.10
6.0.11
6.0.12
6.0.13
6.0.14
6.0.15
6.0.16
6.0.17
6.0.18
6.0.19
6.0.20
6.0.21
6.0.22
6.0.23
6.1.0
6.1.1
6.1.2
6.1.3
6.1.4
6.1.5
6.1.6
6.1.7
6.1.8
6.1.9
6.1.10
6.1.11
6.1.12
6.1.13
6.1.14
6.1.15
6.1.16
6.1.17
6.1.18
6.1.19
6.1.20
6.1.21

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6hcq-hmm3-jj3c/GHSA-6hcq-hmm3-jj3c.json"
org.springframework:spring-webflux

Package

Name
org.springframework:spring-webflux
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webflux

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Last affected
5.3.39

Affected versions

5.*
5.3.0
5.3.1
5.3.2
5.3.3
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9
5.3.10
5.3.11
5.3.12
5.3.13
5.3.14
5.3.15
5.3.16
5.3.17
5.3.18
5.3.19
5.3.20
5.3.21
5.3.22
5.3.23
5.3.24
5.3.25
5.3.26
5.3.27
5.3.28
5.3.29
5.3.30
5.3.31
5.3.32
5.3.33
5.3.34
5.3.35
5.3.36
5.3.37
5.3.38
5.3.39

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6hcq-hmm3-jj3c/GHSA-6hcq-hmm3-jj3c.json"