CVE-2026-47886

Updated on 27 Aug 2026

Severity

4.0 Medium severity

Details

CVSS score
4.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Evaluation of such an expression can consume excessive CPU time and JVM heap memory, leading to application degradation or unavailability.

More precisely, an application can be vulnerable when all the following are true:

  • The application accepts and evaluates untrusted or user-controlled SpEL expressions.
  • A BigDecimal or BigInteger value is accessible within the evaluation context — for example, but not limited to, as a named context variable, a property or field accessible anywhere in the reachable object graph, an element of a reachable collection or map, or the return value of a registered function.

When all conditions are met, an attacker can craft a SpEL expression using the power operator to trigger a computation that monopolizes a thread for minutes to hours and exhausts JVM heap memory, resulting in a Denial of Service.

Details

Fixes