CVSS 9.8, but the code doesn't add up.
CVE-2026-47890 and CVE-2026-59313 in Spring claim critical impact, but:
❌Same root cause: a stray \r corrupting an SSE stream
❌Spring scores both 2.6, Low, same vector
❌CISA scores both 9.8, Critical, no server-side compromise possible
The JFrog Security Research Team empowers developers and companies to excel by identifying, prioritizing, and mitigating software risks.

