CVE-2026-47890 | VMware Spring Framework up to 7.0.8/6.2.19 Server-Sent Events crlf injection (Nessus ID 341190 / WID-SEC-2026-2955)
A vulnerability categorized as critical has been discovered in VMware Spring Framework up to 7.0.8/6.2.19. This affects an unknown function of the component Server-Sent Events. The manipulation results in crlf injection.
This vulnerability is identified as CVE-2026-47890. The attack can be executed remotely. There is not any exploit available.