CVE-2026-59313: unauthenticated stream corruption in Spring Spring Framework

Attackers can cause stream corruption in Spring Framework applications that use the functional web framework Server-Sent Events (SSE). CVE-2026-59313 affects Spring Framework versions 7.0.0–7.0.8, 6.2.0–6.2.19, 6.1.0–6.1.28, 6.0.0–6.0.30 and 5.3.0–5.3.49. According to the published CVSS vector, exploitation can be performed remotely over the network without privileges or user interaction, so an unauthenticated network attacker targeting an exposed SSE endpoint can trigger the issue.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00564
CWE
CWE-93
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this flaw can be triggered without authentication or user interaction, so internet-facing SSE endpoints should be treated as high priority to protect and mitigate immediately.

What is CVE-2026-59313?

Attackers can cause stream corruption in Spring Framework applications that use the functional web framework Server-Sent Events (SSE). CVE-2026-59313 affects Spring Framework versions 7.0.0–7.0.8, 6.2.0–6.2.19, 6.1.0–6.1.28, 6.0.0–6.0.30 and 5.3.0–5.3.49. According to the published CVSS vector, exploitation can be performed remotely over the network without privileges or user interaction, so an unauthenticated network attacker targeting an exposed SSE endpoint can trigger the issue.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Spring Spring Framework are affected?

BRANCHAFFECTEDFIXED
7.x7.0.0 – 7.0.8
6.x6.2.0 – 6.2.19
6.x6.1.0 – 6.1.28
6.x6.0.0 – 6.0.30
5.x5.3.0 – 5.3.49

Is CVE-2026-59313 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-59313

  1. Restrict access to SSE endpoints to trusted networks or via authentication and firewalls
  2. Apply network-level controls to block or limit external access to affected Spring Framework services
  3. Enable and monitor detailed application and SSE logs for unexpected stream errors or anomalies
  4. Follow Spring vendor guidance and apply vendor-supplied fixes as soon as they are published

Frequently asked questions

Is CVE-2026-59313 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which Spring Framework versions are affected by CVE-2026-59313?

The vulnerability affects Spring Framework versions 7.0.0–7.0.8, 6.2.0–6.2.19, 6.1.0–6.1.28, 6.0.0–6.0.30 and 5.3.0–5.3.49.

Is there a patch for CVE-2026-59313?

No fixed versions are listed in the affected data; monitor Spring advisories for published patches and apply them when available.

Does CVE-2026-59313 require authentication?

No. The published vulnerability data indicates exploitation can occur without authentication or user interaction, targeting exposed SSE endpoints.

References