← Back

CVE-2026-22740

nvd nist
Published: Apr 29, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: security@vmware.com (Secondary)

Description

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully processed. This allows an attacker to consume available disk space. Older, unsupported versions are also affected.

Affected (4)

1 product
Spring Framework
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Before 5.3.48
From 6.1.0 to 6.1.27
From 6.2.0 to 6.2.18
From 7.0.0 to 7.0.7

References (2)

Timeline

No history available yet.