CVE-2026-47891: memory limit bypass in Spring Spring Framework

Remote attackers can send XML payloads to a Spring WebFlux endpoint that uses the Aalto XML library and cause the application to allocate more memory than intended, which can produce service disruption from memory exhaustion. This is recorded as CVE-2026-47891. Affected Spring Framework releases include 7.0.0–7.0.8, 6.2.0–6.2.19, 6.1.0–6.1.28, 6.0.0–6.0.30, 5.3.0–5.3.49 and 5.2.25.RELEASE and earlier; any client that can submit XML to such a WebFlux handler can trigger the issue.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00522
CWE
CWE-770
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this allows unauthenticated XML input to drive excessive memory use; immediately restrict access to XML-parsing endpoints and apply request limits while awaiting vendor remediation.

What is CVE-2026-47891?

Remote attackers can send XML payloads to a Spring WebFlux endpoint that uses the Aalto XML library and cause the application to allocate more memory than intended, which can produce service disruption from memory exhaustion. This is recorded as CVE-2026-47891. Affected Spring Framework releases include 7.0.0–7.0.8, 6.2.0–6.2.19, 6.1.0–6.1.28, 6.0.0–6.0.30, 5.3.0–5.3.49 and 5.2.25.RELEASE and earlier; any client that can submit XML to such a WebFlux handler can trigger the issue.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Spring Spring Framework are affected?

BRANCHAFFECTEDFIXED
7.x7.0.0 – 7.0.8
6.x6.2.0 – 6.2.19
6.x6.1.0 – 6.1.28
6.x6.0.0 – 6.0.30
5.x5.3.0 – 5.3.49
5.x5.2.25.RELEASE and earlier

Is CVE-2026-47891 being exploited?

There are no public reports of exploitation of CVE-2026-47891 as of 2026-09-29.

How to fix CVE-2026-47891

  1. Limit network exposure of WebFlux endpoints that accept XML to internal or trusted clients.
  2. Configure request size and timeout limits at the gateway or reverse proxy to block large or slow XML submissions.
  3. Add server-side validation on XML structure and node counts before parsing and enable JVM memory limits and alerting.
  4. Track Spring advisories and deploy vendor patches or recommended updates once published.

Frequently asked questions

Is CVE-2026-47891 being actively exploited?

There are no public reports of exploitation of CVE-2026-47891 as of 2026-09-29.

Which Spring Framework versions are affected by CVE-2026-47891?

Affected versions include Spring Framework 7.0.0–7.0.8, 6.2.0–6.2.19, 6.1.0–6.1.28, 6.0.0–6.0.30, 5.3.0–5.3.49 and 5.2.25.RELEASE and earlier when applications use the Aalto XML parser in WebFlux.

Is there a patch for CVE-2026-47891?

No fixed releases are listed in the provided data; follow Spring project advisories for official patches or mitigation guidance.

Does CVE-2026-47891 require authentication?

No authentication is required in the reported information; any client able to send XML to a vulnerable WebFlux endpoint can potentially trigger the condition.

References