CVE-2026-59277
- EPSS 0.21%
- Veröffentlicht 27.08.2026 17:57:36
- Zuletzt bearbeitet 02.09.2026 16:57:37
Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or external (public) network. Spring S...
CVE-2026-59276
- EPSS 0.26%
- Veröffentlicht 27.08.2026 17:57:34
- Zuletzt bearbeitet 02.09.2026 16:45:37
Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken...
CVE-2026-59354
- EPSS 0.37%
- Veröffentlicht 27.08.2026 06:33:03
- Zuletzt bearbeitet 01.09.2026 16:01:32
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by ...
CVE-2026-59270
- EPSS 0.29%
- Veröffentlicht 27.08.2026 06:17:21
- Zuletzt bearbeitet 01.09.2026 20:36:33
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Securi...
CVE-2026-47877
- EPSS 0.19%
- Veröffentlicht 27.08.2026 06:17:17
- Zuletzt bearbeitet 02.09.2026 15:23:27
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6
CVE-2026-47842
- EPSS 0.15%
- Veröffentlicht 26.08.2026 19:22:23
- Zuletzt bearbeitet 04.09.2026 19:34:25
Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using a null (all-zero) initialization vector. Spring Security 7.1.0 Spring Security 7...
CVE-2026-47841
- EPSS 0.3%
- Veröffentlicht 26.08.2026 17:08:52
- Zuletzt bearbeitet 04.09.2026 19:41:48
An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4....
CVE-2026-41707
- EPSS 0.25%
- Veröffentlicht 25.08.2026 22:34:30
- Zuletzt bearbeitet 24.09.2026 14:27:30
Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, ...
CVE-2026-47838
- EPSS 0.12%
- Veröffentlicht 09.06.2026 23:50:07
- Zuletzt bearbeitet 23.07.2026 09:10:00
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating anothe...
CVE-2026-41706
- EPSS 0.21%
- Veröffentlicht 09.06.2026 23:47:58
- Zuletzt bearbeitet 23.07.2026 09:10:00
Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full...