OSV 1.4.0 · github-reviewed · 修改于 2026-07-31 00:52
发布时间
2026-06-09 14:31
GitHub 审查时间
2026-07-31 00:52
NVD 发布时间
2026-06-09 13:16
源文件
advisories/github-reviewed/2026/06/GHSA-775g-4xr8-78h8/GHSA-775g-4xr8-78h8.json
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS).
Affected versions: Spring Framework 5.3.0 through 5.3.48.