{"id":"GHSA-2827-2mxx-j8pv","summary":"Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service","details":"An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in the application to fail.\n\nAffected versions:\nSpring Retry 2.0.0 through 2.0.12; 1.3.0 through 1.3.4.","aliases":["CVE-2026-41710"],"modified":"2026-07-29T18:41:44.617631Z","published":"2026-06-09T06:31:57Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-29T18:10:44Z","nvd_published_at":"2026-06-09T05:16:35Z","cwe_ids":["CWE-770"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41710"},{"type":"WEB","url":"https://github.com/spring-attic/spring-retry/issues/505"},{"type":"WEB","url":"https://github.com/spring-attic/spring-retry/commit/6f351edae3d3575fffbde3c0f62fef963dacd152"},{"type":"WEB","url":"https://github.com/spring-attic/spring-retry/releases/tag/v2.0.13"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-retry"},{"type":"WEB","url":"https://spring.io/security/cve-2026-41710"}],"affected":[{"package":{"name":"org.springframework.retry:spring-retry","ecosystem":"Maven","purl":"pkg:maven/org.springframework.retry/spring-retry"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.13"}]}],"versions":["2.0.0","2.0.1","2.0.10","2.0.11","2.0.12","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.12","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-2827-2mxx-j8pv/GHSA-2827-2mxx-j8pv.json"}},{"package":{"name":"org.springframework.retry:spring-retry","ecosystem":"Maven","purl":"pkg:maven/org.springframework.retry/spring-retry"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3.4"}]}],"versions":["1.0.0.RELEASE","1.0.1.RELEASE","1.0.2.RELEASE","1.0.3.RELEASE","1.1.0.RELEASE","1.1.1.RELEASE","1.1.2.RELEASE","1.1.3.RELEASE","1.1.4.RELEASE","1.1.5.RELEASE","1.2.0.RELEASE","1.2.1.RELEASE","1.2.2.RELEASE","1.2.3.RELEASE","1.2.4.RELEASE","1.2.5.RELEASE","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-2827-2mxx-j8pv/GHSA-2827-2mxx-j8pv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}