โ† All reports

The Spring Security framework has multiple vulnerabilities that could lead to security failures if not properly addressed.

CybersecurityTechnologyConflictApr 22, 2026score 0.174 posts ยท 0 replies across 1 instances
This thread discusses multiple vulnerabilities in Spring Security, a widely used framework, highlighting potential security risks in handling certificate CN values, JWT decoding, and user attribute management. These issues could lead to security failures if not addressed, emphasizing the importance of timely updates and proper configuration.

Claims

The Spring Security framework has multiple vulnerabilities that could lead to security failures if not properly addressed.
Parent: Software SecurityEntity: Spring SecurityImpact: negativeDate: Apr 22, 2026Target: The presence and impact of vulnerabilities in Spring Security

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24607 ๐Ÿ“Š Score: 3.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Spring Security, Spring Security, Spring Security (+3 more) ๐Ÿข Vendor: Spring ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenti... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24607 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#isaccountnonexpired#isaccountnonlocked#cybersecurity#infosec#euvd#cve
@[email protected]
๐Ÿšจ EUVD-2026-24609 ๐Ÿ“Š Score: 6.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Spring Security ๐Ÿข Vendor: Spring ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can le... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24609 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24610 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Spring Security, Spring Security, Spring Security (+1 more) ๐Ÿข Vendor: Spring ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24610 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24611 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Spring Security ๐Ÿข Vendor: Spring ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components wi... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24611 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability