Spring Security

Vendor:

First CVE: Oct 4, 2011 · Active for 14 years

36
Total CVEs
More Total CVEs than 97% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Spring Security over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2011
14 years ago
Most Recent CVE
Jun 10, 2026
44 days ago

CVE Severity & Scoring

Spring Security36 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (2.8%)
Network34 (94.4%)
Unknown1 (2.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (83.3%)
High5 (13.9%)
Unknown1 (2.8%)
User Interaction
None32 (88.9%)
Unknown1 (2.8%)
Required3 (8.3%)
Privileges Required
Low8 (22.2%)
High1 (2.8%)
None26 (72.2%)
Unknown1 (2.8%)

Top CVEs

Signals from CVEs in this product scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affe
Mar 19, 20269.135NONO
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet contain
May 19, 20229.834NONO
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully
Jun 10, 20268.133NONO
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a se
Jul 19, 20239.833NONO
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an app
Oct 31, 20229.833NONO
An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded wr
Jun 10, 20267.532NONO
Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a
Apr 22, 20267.531NONO
Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong
Apr 22, 20268.131NONO
When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was
May 25, 20179.830NONO
Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is chang
Feb 23, 20218.829NONO

Exploit Exposure

Signals from CVEs in this product scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (36 CVEs).

Media Mentions

Signals from CVEs in this product scope (36 CVEs).

Top CNAs Publishing CVEs For Spring Security

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.7.915.50.2%00
5.7.1015.50.2%00
5.2.015.32.3%00
5.0.018.12.5%00
4.2.218.12.5%00
4.2.118.12.5%00
4.2.027.82.0%00
4.1.317.51.4%00
4.1.217.51.4%00
4.1.117.51.4%00
4.1.027.52.1%00
4.0.417.52.8%00
4.0.317.52.8%00
4.0.217.52.8%00
4.0.117.52.8%00
4.0.017.52.8%00
3.2.927.52.1%00
3.2.827.52.1%00
3.2.727.52.1%00
3.2.627.52.1%00