org.springframework.security:spring-security-web
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework.security:spring-security-webpage 1 of 1
- CVE-2021-22112HIGHCVSS 8.8EG 8.8✓ Fixed in 5.2.92021-02-23
vulnerable: 3.0.0.RELEASE ... 5.2.8.RELEASE (103 versions)
Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cann…
- CVE-2022-22978CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.4.112022-05-19
vulnerable: 3.0.0.RELEASE ... 5.4.9 (135 versions)
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the…
- CVE-2024-38821CRITICALCVSS 9.1EG 9.1✓ Fixed in 6.3.42024-10-28
vulnerable: 6.3.0, 6.3.1, 6.3.2, 6.3.3
Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must be true: * It must be a WebFlux ap…
- CVE-2026-22732CRITICALCVSS 9.1EG 9.1✓ Fixed in 7.0.42026-03-19
vulnerable: 7.0.0, 7.0.1, 7.0.2, 7.0.3
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (defa…
- CVE-2026-22747MEDIUMCVSS 6.8EG 6.8✓ Fixed in 7.0.52026-04-22
vulnerable: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certific…
Check whether org.springframework.security:spring-security-web is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework.security:spring-security-web CVEs against the assets you own.
Start Free Scan →