CVE-2024-38828: Spring
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.
Affected products
- Spring Spring: from 5.3, before 5.3.42 (fixed in 5.3.42)
- VMware Spring: from 5.3.0, before 5.3.42 (fixed in 5.3.42)
Published 2024-11-18. Last modified 2026-06-17.