The Spring Security framework has multiple vulnerabilities that could lead to security failures if not properly addressed.
Claims
The Spring Security framework has multiple vulnerabilities that could lead to security failures if not properly addressed.
Parent: Software SecurityEntity: Spring SecurityImpact: negativeDate: Apr 22, 2026Target: The presence and impact of vulnerabilities in Spring Security
Source posts
๐จ EUVD-2026-24607
๐ Score: 3.7/10 (CVSS v3.1)
๐ฆ Product: Spring Security, Spring Security, Spring Security (+3 more)
๐ข Vendor: Spring
๐
Updated: 2026-04-22
๐ Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenti...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24607
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#isaccountnonexpired#isaccountnonlocked#cybersecurity#infosec#euvd#cve
๐จ EUVD-2026-24609
๐ Score: 6.8/10 (CVSS v3.1)
๐ฆ Product: Spring Security
๐ข Vendor: Spring
๐
Updated: 2026-04-22
๐ Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can le...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24609
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24610
๐ Score: 5.3/10 (CVSS v3.1)
๐ฆ Product: Spring Security, Spring Security, Spring Security (+1 more)
๐ข Vendor: Spring
๐
Updated: 2026-04-22
๐ Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24610
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24611
๐ Score: 7.5/10 (CVSS v3.1)
๐ฆ Product: Spring Security
๐ข Vendor: Spring
๐
Updated: 2026-04-22
๐ Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components wi...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24611
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability