GHSA-j9f9-w8pj-32f8

Suggest an improvement
Source
https://github.com/advisories/GHSA-j9f9-w8pj-32f8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-j9f9-w8pj-32f8/GHSA-j9f9-w8pj-32f8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j9f9-w8pj-32f8
Aliases
  • CVE-2026-47890
Downstream
CGA (45)
Published
2026-08-27T06:31:34Z
Modified
2026-10-07T13:30:04Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Spring Framework Server Sent Event stream corruption while rendering fragments
Details

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

Database specific
{
    "cwe_ids": [
        "CWE-93"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T13:20:36Z",
    "nvd_published_at": "2026-08-27T06:17:20Z",
    "severity": "CRITICAL"
}
References

Affected packages

Maven
org.springframework:spring-webflux

Package

Name
org.springframework:spring-webflux
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webflux

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Last Affected
6.2.19

Affected versions

6.*
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.2.10
6.2.11
6.2.12
6.2.13
6.2.14
6.2.15
6.2.16
6.2.17
6.2.18
6.2.19

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-j9f9-w8pj-32f8/GHSA-j9f9-w8pj-32f8.json"
org.springframework:spring-webflux

Package

Name
org.springframework:spring-webflux
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webflux

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.0.9

Affected versions

7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8

Database specific

last_known_affected_version_range
"<= 7.0.8"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-j9f9-w8pj-32f8/GHSA-j9f9-w8pj-32f8.json"
org.springframework:spring-webmvc

Package

Name
org.springframework:spring-webmvc
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webmvc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Last Affected
6.2.19

Affected versions

6.*
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.2.10
6.2.11
6.2.12
6.2.13
6.2.14
6.2.15
6.2.16
6.2.17
6.2.18
6.2.19

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-j9f9-w8pj-32f8/GHSA-j9f9-w8pj-32f8.json"
org.springframework:spring-webmvc

Package

Name
org.springframework:spring-webmvc
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-webmvc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.0.9

Affected versions

7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8

Database specific

last_known_affected_version_range
"<= 7.0.8"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-j9f9-w8pj-32f8/GHSA-j9f9-w8pj-32f8.json"