spring-webflux is vulnerable to Observable Timing Discrepancy
60
Medium Risk
Affected versions of this package are vulnerable to uncontrolled resource consumption in WebFlux multipart request handling because temporary files created for larger multipart parts may not be deleted after request processing completes. An attacker may send crafted multipart requests to accumulate temp files and exhaust available disk space, causing denial of service.
You are affected if using a vulnerable version.
spring-webflux is vulnerable to Observable Timing Discrepancy in versions 5.3.0 - 5.3.47, 6.1.0 - 6.1.26, 6.2.0 - 6.2.17 and 7.0.0 - 7.0.6.
Upgrade the org.springframework:spring-webflux library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant