GHSA-jrv5-8w28-4265HighCVSS 7.4

Spring LDAP has Authentication Bypass with Empty Password

Published
June 9, 2026
Last Modified
July 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired with an empty or null password.

Affected versions: Spring LDAP 2.4.0 through 2.4.4; 3.2.0 through 3.2.17; 3.3.0 through 3.3.7; 4.0.0 through 4.0.3.

🎯 Affected products4

  • maven/org.springframework.ldap:spring-ldap-core:>= 4.0.0, <= 4.0.3
  • maven/org.springframework.ldap:spring-ldap-core:>= 3.3.0, <= 3.3.7
  • maven/org.springframework.ldap:spring-ldap-core:>= 3.2.0, <= 3.2.16
  • maven/org.springframework.ldap:spring-ldap-core:<= 2.4.4

🔗 References (9)