{"id":"CVE-2026-22745","summary":"CVE-2026-22745 : Denial of service in static resource handling on Windows platforms","details":"Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources.\n\n\nMore precisely, an application can be vulnerable when all the following are true:\n\n  *  the application is using Spring MVC or Spring WebFlux\n  *  the application is serving static resources from the file system\n  *  the application is running on a Windows platform\n\n\nWhen all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.","aliases":["GHSA-6p4f-wcwh-5vvm"],"modified":"2026-07-17T21:07:37.633043448Z","published":"2026-04-29T11:35:21.947Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22745.json","unresolved_ranges":[{"extracted_events":[{"introduced":"7.0.0"},{"fixed":"7.0.7"},{"introduced":"6.2.0"},{"fixed":"6.2.18"},{"introduced":"6.1.0"},{"fixed":"6.1.27"},{"introduced":"5.3.0"},{"fixed":"5.3.48"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"vmware","cwe_ids":["CWE-400"]},"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&version=3.1"},{"type":"WEB","url":"https://spring.io/security/cve-2026-22745"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22745.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22745"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/spring-projects/spring-framework","events":[{"introduced":"5024bb72279188f1d0dcfe19e8abdd4bdb9887c8"},{"fixed":"6b117247d383294662e199c6b47d7bf54c49caaa"},{"introduced":"fe00848be255db1455f0189d9ff28661f301be36"},{"fixed":"c997d4018d3dc6a7dde2e20eae3627599a01e169"}],"database_specific":{"source":"CPE_FIELD","cpe":"cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.2.0"},{"fixed":"6.2.18"},{"introduced":"7.0.0"},{"fixed":"7.0.7"}]}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-22745.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}