spring-webflux is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
30
Low Risk
Affected versions of this package are vulnerable to improper cache control in Spring MVC and WebFlux static resource handling, allowing attackers to poison the resource cache with incorrectly encoded resources when specific caching and encoded resource resolution settings are enabled. This can break front-end assets for clients and cause denial of service.
You are affected if using a vulnerable version.
spring-webflux is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 5.3.0 - 5.3.47, 6.1.0 - 6.1.26, 6.2.0 - 6.2.17 and 7.0.0 - 7.0.6.
Upgrade the org.springframework:spring-webflux library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant