Spring / Spring Security
28 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59277 | Spring Security InetAddressMatchers Incomplete Internal Network Classification | MEDIUM | 5.3 | Aug 27, 2026 |
| CVE-2026-59276 | Timing Attack via Non-Constant-Time Comparison of Sensitive Values | MEDIUM | 5.9 | Aug 27, 2026 |
| CVE-2026-59270 | Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces | CRITICAL | 9.4 | Aug 27, 2026 |
| CVE-2026-47877 | Spring Security Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS) | HIGH | 8.2 | Aug 27, 2026 |
| CVE-2026-47842 | Deterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows Ciphertext Correlation | MEDIUM | 6.5 | Aug 26, 2026 |
| CVE-2026-47841 | WebAuthn User Verification Bypass via Session Serialization | HIGH | 7.4 | Aug 26, 2026 |
| CVE-2026-41707 | Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay | HIGH | 7.4 | Aug 25, 2026 |
| CVE-2026-47838 | Unauthorized User Impersonation when Using X.509 Client Certificates | HIGH | 8.1 | Jun 9, 2026 |
| CVE-2026-41706 | Open Redirect When Using CookieRequestCache | MEDIUM | 6.1 | Jun 9, 2026 |
| CVE-2026-41694 | SAML Payloads Decrypted Without Valid Signature | MEDIUM | 5.3 | Jun 9, 2026 |
| CVE-2026-41008 | Spring Security Authorization Server Open Redirect via request_uri | MEDIUM | 6.1 | Jun 9, 2026 |
| CVE-2026-41003 | Unencoded HTML Outputs in Spring Security May Allow Cross-Site Scripting | HIGH | 7.6 | Jun 9, 2026 |
| CVE-2026-40993 | Unfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database Entry | HIGH | 7.3 | Jun 9, 2026 |
| CVE-2026-40988 | Unbounded DEFLATE Inflation in SAML 2.0 Service Provider | HIGH | 7.5 | Jun 9, 2026 |
| CVE-2026-22754 | ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules | HIGH | 7.5 | Apr 22, 2026 |
| CVE-2026-22753 | Servlet Path Not Correctly Included in Path Matching of HttpSecurity#securityMatchers | HIGH | 7.5 | Apr 22, 2026 |
| CVE-2026-22748 | Potential Security Misconfiguration when Using withIssuerLocation | MEDIUM | 6.5 | Apr 22, 2026 |
| CVE-2026-22747 | Unauthorized User Impersonation when Using X.509 Client Certificates | HIGH | 8.1 | Apr 22, 2026 |
| CVE-2026-22746 | User Attribute Enumeration when Using DaoAuthenticationProvider | LOW | 3.7 | Apr 22, 2026 |
| CVE-2026-22751 | Spring Security JdbcOneTimeTokenService allows a one-time token to authenticate multiple sessions | MEDIUM | 4.8 | Apr 21, 2026 |
| CVE-2026-22733 | Authentication Bypass under Actuator CloudFoundry endpoints | HIGH | 8.2 | Mar 19, 2026 |
| CVE-2025-22234 | Spring Security - BCrypt Password Encoder maximum password length breaks timing attack mitigation | MEDIUM | 5.3 | Jan 22, 2026 |
| CVE-2025-41232 | CVE-2025-41232: Spring Security authorization bypass for method security annotations on private methods | CRITICAL | 9.1 | May 21, 2025 |
| CVE-2025-22223 | spring-security: authorization bypass via incorrectly locating method security annotations on parameterized types or methods | MEDIUM | 5.3 | Mar 24, 2025 |
| CVE-2025-22228 | CVE-2025-22228: Spring Security BCryptPasswordEncoder does not enforce maximum password length | HIGH | 7.4 | Mar 20, 2025 |
Showing 1 to 25 of 28 CVEs