CVE-2026-59283CWE-913

CVE-2026-59283

Critical · published August 28, 2026

CVSS v3.1
9.1
EPSS
0%
Percentile
30.5
In the wild
Unconfirmed
What it is

Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active.

Spring Framework 7.0.0 - 7.0.8

Spring Framework 6.2.0 - 6.2.19

Spring Framework 6.1.0 - 6.1.28

Spring Framework 6.0.0 - 6.0.30

Spring Framework 5.3.0 - 5.3.49

Spring Framework 5.2.25.RELEASE and earlier

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00374 · 30.5th percentile
Weakness
CWE-913 · Improper Control of Dynamically-Managed Code Resources
Published
2026-08-28T00:17Z
Affected products (6)
ProductVersionsFixed in
vmware/spring_framework< 5.2.265.2.26
vmware/spring_framework≥ 5.3.0, < 5.3.505.3.50
vmware/spring_framework≥ 6.0.0, < 6.0.316.0.31
vmware/spring_framework≥ 6.1.0, < 6.1.296.1.29
vmware/spring_framework≥ 6.2.0, < 6.2.206.2.20
vmware/spring_framework≥ 7.0.0, < 7.0.8.17.0.8.1
References (1)
EPSS history
Timeline
  • 27 AUG 17:57Z
    Spring Framework Safety Guard Bypass via SpEL Expression Compilation
    cvelistv5