Critical Vulnerability in Spring Framework: CVE-2026-47891
A critical vulnerability (CVE-2026-47891) with a CVSS score of 9.8 affects multiple versions of the Spring Framework, allowing for remote code execution. The vulnerability occurs due to incorrect enforcement of the maxInMemorySize limit in Spring WebFlux applications relying on the Aalto XML processor. Immediate patching is recommended to prevent potential exploitation.