Spring Security
6 known vulnerabilities in Spring Security, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-59277 CVSS 5.3 medium Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher…
- CVE-2026-59276 CVSS 5.9 medium Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a…
- CVE-2026-59270 CVSS 9.1 critical Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its…
- CVE-2026-47877 CVSS 6.1 medium Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security…
- CVE-2026-47842 CVSS 6.5 medium Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode…
- CVE-2026-47841 CVSS 7.4 high An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP…