{"id":"CVE-2024-38808","aliases":["GHSA-9cmq-m9j5-mvww"],"url":"https://o3.security/vulnerability/CVE-2024-38808","summary":"CVE-2024-38808: Spring Expression DoS Vulnerability","details":"In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Older, unsupported versions are also affected.\n\nSpecifically, an application is vulnerable when the following is true:\n\n  *  The application evaluates user-supplied SpEL expressions.","published":"2024-08-20T07:12:44.736Z","modified":"2026-08-12T03:51:29.564551237Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"},"epss":{"score":0.00568,"percentile":0.43934,"asOf":"2026-08-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.springframework:spring-expression","fixedVersion":"5.3.39"}],"fix":{"url":"https://github.com/spring-projects/spring-framework/commit/26f2dad388499faecf99e75b8856788e95d8d658","label":"spring-projects/spring-framework@26f2dad"},"references":[{"type":"WEB","url":"https://spring.io/security/cve-2024-38808"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38808.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38808"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240920-0002/"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/26f2dad388499faecf99e75b8856788e95d8d658"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/f44d13cb7816e586b86c02421af4f5498391111c"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-framework"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20240920-0002"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:29.564551237Z"}}