CVE-2026-22732 is a critical vulnerability affecting Spring Security Servlet applications across multiple versions (5.7.0-7.0.3) where HTTP response headers may not be written when using lazy (default) writing. This flaw, rated 9.1 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), allows an unauthenticated, remote attacker to bypass security policies like Content Security Policy (CSP) or HTTP Strict Transport Security (HSTS) due to missing headers, potentially leading to high impact on confidentiality and integrity. Although no public exploit code is currently available and it is not listed in CISA KEV, the vulnerability is being discussed in the community and has received media attention, suggesting a need for urgent patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.7.0, <= 5.7.21CPE match | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 5.8.0, <= 5.8.23CPE match | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 6.3.0, <= 6.3.14CPE match | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 6.4.0, <= 6.4.14CPE match | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | ||
>= 6.5.0, <= 6.5.8CPE match | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.