Affected versions:
Spring Retry 2.0.0 through 2.0.12; 1.3.0 through 1.3.4.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-41710 |
|
Tue, 09 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Retry |
|
| Vendors & Products |
Spring
Spring spring Retry |
Tue, 09 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in the application to fail. Affected versions: Spring Retry 2.0.0 through 2.0.12; 1.3.0 through 1.3.4. | |
| Title | Cache Exhaustion in Stateful Retries leads to Denial of Service | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-23T20:40:24.254Z
Reserved: 2026-04-22T06:21:34.490Z
Link: CVE-2026-41710
Updated: 2026-06-09T13:43:58.061Z
Status : Awaiting Analysis
Published: 2026-06-09T05:16:35.147
Modified: 2026-06-09T13:49:39.993
Link: CVE-2026-41710
No data.
OpenCVE Enrichment
Updated: 2026-06-09T08:55:49Z