Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryidentity-authentication-vulnerabilityopen-source-dependency-vulnerabilityinternet-facing-service-vulnerability

Spring patches LDAP auth bypass and multiple DoS flaws across Framework and Data

Updated 12d agoFirst seen Jun 9, 202611 sources

Spring disclosed a broad set of vulnerabilities across Spring Framework, Spring Data Commons, and Spring LDAP, including a high-severity authentication bypass tracked as CVE-2026-41720. The LDAP flaw allows login with a valid username and an empty or null password when the backing LDAP server permits unauthenticated binds, affecting authentication flows that use AbstractContextSource, LdapTemplate, or LdapClient. Spring also fixed a low-severity WebFlux session fixation issue (CVE-2026-41839) tied to compromised subdomains, and an information disclosure bug (CVE-2026-41841) in Spring MVC and WebFlux where shared static-resource caches could expose protected files if a public resource with the same name had already been cached.

Several denial-of-service issues were patched at the same time. In Spring Framework, CVE-2026-41840 can leak memory through malicious multipart requests in WebFlux, while CVE-2026-41842 can tie up HTTP connections through slow resolution of versioned file-system resources in Spring MVC or WebFlux. In Spring Data Commons, CVE-2026-41695, CVE-2026-41711, CVE-2026-41716, and CVE-2026-41721 can be triggered by attacker-controlled property paths, sort parameters, property names, or @ProjectedPayload data binding, leading to stack overflows, heap exhaustion, or excessive memory allocation when applications expose those inputs to untrusted users. Spring urged customers to upgrade to fixed releases, including Framework 7.0.8, 6.2.19, and 6.1.28, Data Commons 4.0.6 and 3.5.12, and LDAP 2.4.5, 3.2.18, 3.3.8, or 4.0.4, with some older branches receiving fixes only through commercial support.

Share:
Spring patches LDAP auth bypass and multiple DoS flaws across Framework and Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Jun 11, 202612d ago

Security Online reports three additional patched Spring Data vulnerabilities

Security Online reported three additional Spring Data flaws not captured in the existing timeline: CVE-2026-41729 and CVE-2026-41717, described as injection vulnerabilities that can lead to remote code execution, and CVE-2026-41728, which can bypass Jackson read-only property protections on nested objects. The report said Spring released patches and specifically directed Spring Data REST 4.5.x users to upgrade to version 4.5.12.

Spring Data Vulnerabilities: Patch 5 Critical Flaws Now
Jun 9, 202614d ago

Security Online reports Spring patched multiple newly disclosed flaws

Security Online reported that multiple newly addressed Spring vulnerabilities had been patched, highlighting CVE-2026-41720 as the most critical and urging administrators to upgrade to Spring Framework 7.0.8, 6.2.19, or 6.1.28 and validate environments with regression testing. The article summarized the already disclosed issues affecting authentication, denial of service, information disclosure, and session fixation.

Spring Framework Security Vulnerabilities Patched

Spring discloses CVE-2026-41721 data binding DoS in Spring Data Commons

Spring disclosed CVE-2026-41721, a medium-severity denial-of-service vulnerability in Spring Data Commons where crafted HTTP requests can trigger excessive memory allocation when Spring Data Web Support and @ProjectedPayload are used. Spring advised users to upgrade to fixed releases such as 4.0.6 and 3.5.12.

CVE-2026-41721: Spring Data Commons Denial of Service via Data Binding

Spring discloses CVE-2026-41716 negative-result cache DoS

Spring disclosed CVE-2026-41716, a high-severity denial-of-service vulnerability in Spring Data web support caused by an internal property-lookup cache that permanently retains attacker-supplied strings as keys, potentially leading to heap exhaustion. Spring said OSS fixes are available in 3.5.12 and 4.0.6, with commercial fixes for additional branches.

CVE-2026-41716: Spring Data web support unbounded negative-result cache keyed on attacker-supplied property names

Spring discloses CVE-2026-41711 crafted Sort parameter DoS

Spring disclosed CVE-2026-41711, a medium-severity denial-of-service vulnerability in Spring Data Commons where crafted Sort parameters can trigger a StackOverflowException during parsing. Spring recommended upgrading to fixed releases and sanitizing untrusted sorting input.

CVE-2026-41711: Potential Denial of Service through crafted Sort Parameters

Spring discloses CVE-2026-41695 property path resolution DoS

Spring disclosed CVE-2026-41695, a high-severity denial-of-service vulnerability in Spring Data Commons caused by resource exhaustion during MappingContext property path resolution when attacker-controlled property paths are exposed. Spring advised upgrading to fixed versions 4.0.6, 3.5.12, or 3.4.15.

CVE-2026-41695: Denial of Service in Spring Data Commons Property Path Resolution
Jun 8, 202615d ago

Spring publishes CVE-2026-41842 slow-request DoS via versioned resources

Spring disclosed CVE-2026-41842, a high-severity denial-of-service flaw affecting Spring MVC and WebFlux applications serving file-system static resources with versioned resource support enabled. Malicious requests can be slow to resolve and tie up HTTP connections, and Spring recommended upgrading to fixed releases including 7.0.8, 6.2.19, 6.1.28, or 5.3.49.

CVE-2026-41842: Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

Spring publishes CVE-2026-41841 static resource cache disclosure flaw

Spring disclosed CVE-2026-41841, an information disclosure vulnerability in Spring MVC and WebFlux that can expose protected resources when shared caches are used across differently protected resource handlers. Spring stated that upgrading to fixed releases is sufficient and no additional mitigation is necessary.

CVE-2026-41841: Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

Spring publishes CVE-2026-41840 multipart-request DoS in WebFlux

Spring disclosed CVE-2026-41840, a medium-severity denial-of-service vulnerability in Spring Framework WebFlux where malicious multipart requests can leak memory and exhaust resources. Spring said affected users should upgrade to fixed releases such as 7.0.8 and 6.2.19.

CVE-2026-41840: Spring Framework Denial of Service via Multipart Requests in WebFlux

Spring publishes CVE-2026-41839 session fixation issue in WebFlux

Spring disclosed CVE-2026-41839, a low-severity session fixation-related escalation issue affecting WebFlux applications with a compromised subdomain. The company advised customers to upgrade to fixed releases including 7.0.8 and 6.2.19.

CVE-2026-41839: Spring Framework Escalation via Session Fixation in WebFlux

Spring publishes CVE-2026-41720 authentication bypass in Spring LDAP

Spring disclosed CVE-2026-41720, a high-severity authentication bypass flaw in Spring LDAP where a valid username paired with an empty or null password can succeed on LDAP servers that permit unauthenticated binds. Spring recommended upgrading to fixed releases 2.4.5, 3.2.18, 3.3.8, or 4.0.4.

CVE-2026-41720: Authentication Bypass with Empty Password in Spring LDAP
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.