An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in the application to fail.
Affected versions: Spring Retry 2.0.0 through 2.0.12; 1.3.0 through 1.3.4.
{
"cna_assigner": "vmware",
"cwe_ids": [
"CWE-770"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41710.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.12.1"
},
{
"introduced": "1.3.0"
},
{
"fixed": "1.3.5"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.12"
},
{
"introduced": "1.3.0"
},
{
"fixed": "1.3.4"
}
],
"source": "DESCRIPTION"
}
]
}