CVE-2026-22735
Java vulnerability analysis and mitigation

Overview

CVE-2026-22735 is a Server-Sent Events (SSE) stream corruption vulnerability in Spring MVC and Spring WebFlux applications. It was disclosed on March 19, 2026, and affects Spring Framework versions 7.0.0–7.0.5, 6.2.0–6.2.16, 6.1.0–6.1.25, and 5.3.0–5.3.46; older unsupported versions are also vulnerable. The vulnerability carries a CVSS v3.1 base score of 2.6 (Low), reflecting the high attack complexity and multiple preconditions required for exploitation (Spring Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified under CWE-667 (Improper Locking) and CWE-115 (Misinterpretation of Input), where inadequate synchronization mechanisms in the SSE stream handling code allow data interleaving or corruption during concurrent writes. Exploitation requires four simultaneous conditions: the application uses Spring MVC or WebFlux, it streams data via SSE, the attacker controls data that will be streamed to other users, and the application uses plain text (not structured formats like JSON) for SSE messages. The attack vector is network-based, requires low-privilege authentication, high attack complexity, and user interaction, making opportunistic exploitation unlikely (Spring Advisory, Red Hat Bugzilla). The vulnerability is associated with race condition attack patterns (CAPEC-25, CAPEC-26, CAPEC-27).

Impact

Successful exploitation results in corruption of SSE data streams delivered to other users of the application, with a limited integrity impact and no confidentiality or availability impact. Depending on how the frontend application processes SSE data, this could lead to corrupted application state or the presentation of malicious or misleading information to other users. The scope is confined to the SSE stream itself and does not enable remote code execution, privilege escalation, or lateral movement (Spring Advisory, Feedly).

Mitigation and workarounds

Users of affected versions should upgrade to the corresponding fixed release: Spring Framework 7.0.6, 6.2.17, 6.1.26, or 5.3.47. No additional configuration-based workarounds are required beyond upgrading. As an interim measure prior to patching, organizations can implement network-level access controls to restrict SSE endpoint access to authenticated users, and consider switching SSE message formats to structured formats like JSON to reduce corruption impact (Spring Advisory). IBM has also released fixes for affected products including CloudPak for AIOps, watsonx.data, Operational Decision Manager, Library Support for Spring, and Business Automation Insights (IBM CloudPak Advisory, IBM Library Spring).

Community reactions

The Spring team credited Gyu-hyeok Lee (g2h) for responsibly reporting the vulnerability, and the advisory was published on March 19, 2026 (Spring Advisory). Security news outlets such as Security Online covered the vulnerability as part of a broader Spring Framework vulnerability roundup alongside CVE-2026-22737. HeroDevs published a March 2026 Spring CVE roundup summarizing six new vulnerabilities patched across the Spring ecosystem (HeroDevs Blog). Community reaction has been measured given the low CVSS score and the multiple preconditions required for exploitation.

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p279-2cqp-84jgCRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesJul 24, 2026
GHSA-fp43-vj7g-pg92HIGH7.5
  • Java logoJava
  • org.omnifaces:omnifaces
NoYesJul 24, 2026
GHSA-7ppr-r889-mcf2HIGH7.5
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.12
NoYesJul 24, 2026
GHSA-mhvj-jhpq-885vHIGH7.4
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.13
NoYesJul 24, 2026
GHSA-46q4-43ph-c6frHIGH7.4
  • Java logoJava
  • org.http4s:blaze-http_2.12
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management