DIRAS TAKE
Treat this as high priority: the vulnerability has a critical CVSS 9.8 rating and no fix is currently listed for affected Spring Framework branches. If your applications use SSE with view fragments, reduce exposure and prepare to patch as soon as vendor fixes are released.
What is CVE-2026-47890?
Remote attackers can cause stream corruption in Spring Framework applications that use Server-Sent Events (SSE) with view fragments, tracked as CVE-2026-47890. The issue affects Spring Framework 7.0.0 through 7.0.8 and 6.2.0 through 6.2.19. The CVSS vector indicates a network attacker can exploit this without authentication or user interaction; the flaw specifically arises in SSE handling when view fragments are in use. No vendor-fixed releases are listed in the advisory data.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Spring Spring Framework are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.0.0 – 7.0.8 | |
| 6.x | 6.2.0 – 6.2.19 |
Is CVE-2026-47890 being exploited?
There are no public reports of exploitation or public exploit code as of 2026-09-29.
How to fix CVE-2026-47890
- If possible, disable or avoid using Server-Sent Events with view fragments until a vendor fix is available.
- Restrict access to affected Spring Framework applications to trusted networks and block unnecessary internet exposure.
- Monitor server logs and SSE endpoints for anomalous stream behavior and increased error rates.
- Apply vendor guidance and install the vendor-provided fixes as soon as patched Spring Framework versions are released.
Frequently asked questions
Is CVE-2026-47890 being actively exploited?
There are no public reports of exploitation or public exploit code for CVE-2026-47890 as of 2026-09-29.
Which Spring Framework versions are affected by CVE-2026-47890?
Spring Framework 7.0.0 through 7.0.8 and 6.2.0 through 6.2.19 are listed as affected.
Is there a patch for CVE-2026-47890?
No fixed versions are listed in the advisory data; there is no patch available in the provided facts.
Does CVE-2026-47890 require authentication?
The CVSS details indicate no privileges and no user interaction are required, meaning exploitation can be performed without authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-47890
- cve.org/CVERecord?id=CVE-2026-47890
- spring.io/security/cve-2026-47890
- All Spring CVEs on CVE Radar
- CVEs published in September 2026