This article clarifies whether Symantec Data Loss Prevention (DLP) is impacted by the Spring Security vulnerability identified as CVE-2026-41838.
Symantec DLP16.1, 25.1, 26.1
NA
Symantec Data Loss Prevention is not impacted by CVE-2026-41838.
This vulnerability specifically affects applications that utilize the Spring WebSocket framework. Symantec DLP does not use Spring WebSocket in its architecture; therefore, the vulnerability cannot be exploited within the DLP environment.