CRITICAL 9.8 CVE-2026-47890 Published 27 Aug 2026

Spring MVC/WebFlux SSE View Fragment Bug

Worried this affects one of your servers?

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments.

Spring Framework versions 7.0.0 to 7.0.8 and 6.2.0 to 6.2.19 are affected.

Reference: CVE-2026-47890 on NVD

← Back to Security News