CVE-2026-41710: Broadcom Spring Retry

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in the application to fail. Affected versions: Spring Retry 2.0.0 through 2.0.12; 1.3.0 through 1.3.4.

Affected products

  • Broadcom Spring Retry: before 1.3.5 (fixed in 1.3.5); from 2.0.0, before 2.0.12.1 (fixed in 2.0.12.1)

Published 2026-06-09. Last modified 2026-09-04.