Intel

AIKIDO-2026-10572

spring-webflux is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CVE-2026-22741 Published Apr 27, 2026

30

Low Risk

This Affects:

JAVAspring-webflux
5.3.0 - 5.3.47
Fixed in 5.3.48
6.1.0 - 6.1.26
Fixed in 6.1.27
6.2.0 - 6.2.17
Fixed in 6.2.18
7.0.0 - 7.0.6
Fixed in 7.0.7
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper cache control in Spring MVC and WebFlux static resource handling, allowing attackers to poison the resource cache with incorrectly encoded resources when specific caching and encoded resource resolution settings are enabled. This can break front-end assets for clients and cause denial of service.

Who does this affect?

You are affected if using a vulnerable version.

Background info

spring-webflux is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 5.3.0 - 5.3.47, 6.1.0 - 6.1.26, 6.2.0 - 6.2.17 and 7.0.0 - 7.0.6.

How to fix this

Upgrade the org.springframework:spring-webflux library to the patch version.