Critical · published August 28, 2026
Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
| Product | Versions | Fixed in |
|---|---|---|
| vmware/spring_framework | < 5.2.26 | 5.2.26 |
| vmware/spring_framework | ≥ 5.3.0, < 5.3.50 | 5.3.50 |
| vmware/spring_framework | ≥ 6.0.0, < 6.0.31 | 6.0.31 |
| vmware/spring_framework | ≥ 6.1.0, < 6.1.29 | 6.1.29 |
| vmware/spring_framework | ≥ 6.2.0, < 6.2.20 | 6.2.20 |
| vmware/spring_framework | ≥ 7.0.0, < 7.0.8.1 | 7.0.8.1 |