CVE-2024-38809: VMware Spring Framework

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the corresponding fixed version. Users of older, unsupported versions could enforce a size limit on "If-Match" and "If-None-Match" headers, e.g. through a Filter.

Affected products

  • VMware Spring Framework: from 6.1.0, up to and including 6.1.11; from 6.0.0, up to and including 6.0.22; from 5.3.0, up to and including 5.3.37

Published 2024-09-27. Last modified 2026-06-17.