CVE-2026-59313: VMware Spring Framework
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49
Affected products
- VMware Spring Framework: from 5.3.0, up to and including 5.3.49; from 6.0.0, up to and including 6.0.30; from 6.1.0, up to and including 6.1.28; from 6.2.0, up to and including 6.2.19; from 7.0.0, up to and including 7.0.8
Published 2026-08-27. Last modified 2026-08-31.