
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22735 is a Server-Sent Events (SSE) stream corruption vulnerability in Spring MVC and Spring WebFlux applications. It was disclosed on March 19, 2026, and affects Spring Framework versions 7.0.0–7.0.5, 6.2.0–6.2.16, 6.1.0–6.1.25, and 5.3.0–5.3.46; older unsupported versions are also vulnerable. The vulnerability carries a CVSS v3.1 base score of 2.6 (Low), reflecting the high attack complexity and multiple preconditions required for exploitation (Spring Advisory, Red Hat Bugzilla).
The root cause is classified under CWE-667 (Improper Locking) and CWE-115 (Misinterpretation of Input), where inadequate synchronization mechanisms in the SSE stream handling code allow data interleaving or corruption during concurrent writes. Exploitation requires four simultaneous conditions: the application uses Spring MVC or WebFlux, it streams data via SSE, the attacker controls data that will be streamed to other users, and the application uses plain text (not structured formats like JSON) for SSE messages. The attack vector is network-based, requires low-privilege authentication, high attack complexity, and user interaction, making opportunistic exploitation unlikely (Spring Advisory, Red Hat Bugzilla). The vulnerability is associated with race condition attack patterns (CAPEC-25, CAPEC-26, CAPEC-27).
Successful exploitation results in corruption of SSE data streams delivered to other users of the application, with a limited integrity impact and no confidentiality or availability impact. Depending on how the frontend application processes SSE data, this could lead to corrupted application state or the presentation of malicious or misleading information to other users. The scope is confined to the SSE stream itself and does not enable remote code execution, privilege escalation, or lateral movement (Spring Advisory, Feedly).
Users of affected versions should upgrade to the corresponding fixed release: Spring Framework 7.0.6, 6.2.17, 6.1.26, or 5.3.47. No additional configuration-based workarounds are required beyond upgrading. As an interim measure prior to patching, organizations can implement network-level access controls to restrict SSE endpoint access to authenticated users, and consider switching SSE message formats to structured formats like JSON to reduce corruption impact (Spring Advisory). IBM has also released fixes for affected products including CloudPak for AIOps, watsonx.data, Operational Decision Manager, Library Support for Spring, and Business Automation Insights (IBM CloudPak Advisory, IBM Library Spring).
The Spring team credited Gyu-hyeok Lee (g2h) for responsibly reporting the vulnerability, and the advisory was published on March 19, 2026 (Spring Advisory). Security news outlets such as Security Online covered the vulnerability as part of a broader Spring Framework vulnerability roundup alongside CVE-2026-22737. HeroDevs published a March 2026 Spring CVE roundup summarizing six new vulnerabilities patched across the Spring ecosystem (HeroDevs Blog). Community reaction has been measured given the low CVSS score and the multiple preconditions required for exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."