CVE-2026-59316
- EPSS 0.19%
- Veröffentlicht 27.08.2026 18:04:44
- Zuletzt bearbeitet 31.08.2026 23:39:56
Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored serve...
CVE-2026-59355
- EPSS 0.23%
- Veröffentlicht 27.08.2026 06:35:09
- Zuletzt bearbeitet 01.09.2026 16:08:13
In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated red...
CVE-2026-22752
- EPSS 0.45%
- Veröffentlicht 16.07.2026 08:40:23
- Zuletzt bearbeitet 04.09.2026 20:06:02
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through ...
CVE-2026-41008
- EPSS 0.17%
- Veröffentlicht 09.06.2026 23:47:07
- Zuletzt bearbeitet 23.07.2026 09:10:00
Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redir...