vmware / spring_security
14 known vulnerabilities in vmware spring_security.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-59354 | Medium | 0.5% | 9.6 | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 throug… | |
| CVE-2026-40988 | Medium | 0.3% | 7.5 | An application using spring-security-saml2-service-provider and the REDIRECT bin… | |
| CVE-2026-47841 | Medium | 0.3% | 7.4 | An application using Spring Security's WebAuthn support may be vulnerable to use… | |
| CVE-2026-59270 | Medium | 0.3% | 9.4 | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditio… | |
| CVE-2026-41003 | Medium | 0.2% | 7.6 | An attacker able to influence values in RelyingPartyRegistration may be able to … | |
| CVE-2026-40993 | Medium | 0.2% | 7.3 | An attacker with write permissions to the database table managed by JdbcAssertin… | |
| CVE-2026-47877 | Medium | 0.2% | 8.2 | Spring Security Authorization Server's default consent page renders user-control… | |
| CVE-2026-59276 | Low | 0.3% | 5.9 | Several components in Spring Security compare security-sensitive values using st… | |
| CVE-2026-41706 | Low | 0.2% | 6.1 | Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-… | |
| CVE-2026-59277 | Low | 0.2% | 3.7 | Spring Security's InetAddressMatchers utility provides matchInternal() and match… | |
| CVE-2026-41008 | Low | 0.2% | 6.1 | Spring Security Authorization Server's authorization endpoint performs insuffici… | |
| CVE-2026-41694 | Low | 0.1% | 3.7 | Since Spring Security SAML decrypts SAML Responses as well as elements of SAML L… | |
| CVE-2026-47838 | Low | 0.1% | 6.8 | SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.50… | |
| CVE-2026-47842 | Low | 0.1% | 6.5 | Applications using AesBytesEncryptor with the two-argument constructor or when p… |