Vmware
Vmware Spring Security: vulnerabilidades y CVE
Vmware Spring Security tiene 50 vulnerabilidades publicadas, 24 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE50
Últimos 12 meses24
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-80515 | Alta (8.9) | 0.47% | — | 3 sept 2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling… |
| CVE-2026-59277 | Media (5.3) | 0.29% | — | 27 ago 2026 | Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or… |
| CVE-2026-59276 | Media (5.9) | 0.33% | — | 27 ago 2026 | Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a… |
| CVE-2026-59354 | Alta (8.8) | 0.49% | — | 27 ago 2026 | In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain… |
| CVE-2026-59270 | Crítica (9.1) | 0.40% | — | 27 ago 2026 | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring… |
| CVE-2026-47877 | Media (6.1) | 0.28% | — | 27 ago 2026 | Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 |
| CVE-2026-47842 | Media (6.5) | 0.15% | — | 26 ago 2026 | Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using a null (all-zero) initialization vector. Spring… |
| CVE-2026-47841 | Alta (7.4) | 0.36% | — | 26 ago 2026 | An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security… |
| CVE-2026-41707 | Alta (7.4) | 0.39% | — | 25 ago 2026 | Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID… |
| CVE-2026-8338 | Crítica (9.2) | 0.50% | — | 29 jul 2026 | A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is… |
| CVE-2026-47838 | Alta (8.1) | 0.19% | — | 10 jun 2026 | SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to… |
| CVE-2026-41706 | Media (6.1) | 0.30% | — | 10 jun 2026 | Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login.… |
| CVE-2026-41694 | Media (5.3) | 0.18% | — | 10 jun 2026 | Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the… |
| CVE-2026-41008 | Media (6.1) | 0.25% | — | 10 jun 2026 | Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and… |
| CVE-2026-41003 | Media (5.4) | 0.25% | — | 10 jun 2026 | An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0… |
| CVE-2026-40993 | Alta (7.2) | 0.30% | — | 10 jun 2026 | An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the… |
| CVE-2026-40988 | Alta (7.5) | 0.46% | — | 10 jun 2026 | An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML… |
| CVE-2026-22754 | Alta (7.5) | 0.27% | — | 22 abr 2026 | Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet path is… |
| CVE-2026-22753 | Alta (7.5) | 0.25% | — | 22 abr 2026 | Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and… |
| CVE-2026-22748 | Media (6.5) | 0.20% | — | 22 abr 2026 | Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling… |
| CVE-2026-22747 | Alta (8.1) | 0.30% | — | 22 abr 2026 | Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully… |
| CVE-2026-22746 | Baja (3.7) | 0.21% | — | 22 abr 2026 | Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then… |
| CVE-2026-22751 | Media (4.8) | 0.12% | — | 21 abr 2026 | Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects… |
| CVE-2026-22732 | Crítica (9.1) | 0.48% | — | 19 mar 2026 | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications… |
| CVE-2025-41248 | Alta (7.5) | 0.43% | — | 16 sept 2025 | The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using… |
| CVE-2025-22223 | Media (5.3) | 0.50% | — | 24 mar 2025 | Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are not affected if you are not using… |
| CVE-2025-22228 | Alta (7.4) | 0.60% | — | 20 mar 2025 | BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same. |
| CVE-2024-38810 | Alta (7.5) | 0.46% | — | 20 ago 2024 | Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective. |
| CVE-2024-22257 | Alta (8.2) | 0.96% | — | 18 mar 2024 | In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken… |
| CVE-2024-22234 | Alta (7.4) | 0.68% | — | 20 feb 2024 | In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the… |