Intel

AIKIDO-2026-10573

spring-webflux is vulnerable to Observable Timing Discrepancy

Observable Timing DiscrepancyCVE-2026-22740 Published Apr 27, 2026

60

Medium Risk

This Affects:

JAVAspring-webflux
5.3.0 - 5.3.47
Fixed in 5.3.48
6.1.0 - 6.1.26
Fixed in 6.1.27
6.2.0 - 6.2.17
Fixed in 6.2.18
7.0.0 - 7.0.6
Fixed in 7.0.7
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to uncontrolled resource consumption in WebFlux multipart request handling because temporary files created for larger multipart parts may not be deleted after request processing completes. An attacker may send crafted multipart requests to accumulate temp files and exhaust available disk space, causing denial of service.

Who does this affect?

You are affected if using a vulnerable version.

Background info

spring-webflux is vulnerable to Observable Timing Discrepancy in versions 5.3.0 - 5.3.47, 6.1.0 - 6.1.26, 6.2.0 - 6.2.17 and 7.0.0 - 7.0.6.

How to fix this

Upgrade the org.springframework:spring-webflux library to the patch version.