9.1
CVE-2026-22732
- EPSS 0.03%
- Veröffentlicht 19.03.2026 22:47:38
- Zuletzt bearbeitet 16.04.2026 04:29:24
- Quelle security@vmware.com
- CVE-Watchlists
- Unerledigt
Under Some Conditions Spring Security HTTP Headers Are not Written
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring Security Version < 5.7.22
VMware ≫ Spring Security Version >= 5.8.0 < 5.8.24
VMware ≫ Spring Security Version >= 6.3.0 < 6.3.15
VMware ≫ Spring Security Version >= 6.4.0 < 6.4.15
VMware ≫ Spring Security Version >= 6.5.0 < 6.5.9
VMware ≫ Spring Security Version >= 7.0.0 < 7.0.4
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.075 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@vmware.com | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-425 Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.