Spring Security
Vendor:
First CVE: Oct 4, 2011 · Active for 14 years
36
Total CVEs
More Total CVEs than 97% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spring Security over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2011
14 years ago
Most Recent CVE
Jun 10, 2026
44 days ago
CVE Severity & Scoring
Spring Security36 CVEs
39%
44%
14%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.8%)
Network34 (94.4%)
Unknown1 (2.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (83.3%)
High5 (13.9%)
Unknown1 (2.8%)
User Interaction
None32 (88.9%)
Unknown1 (2.8%)
Required3 (8.3%)
Privileges Required
Low8 (22.2%)
High1 (2.8%)
None26 (72.2%)
Unknown1 (2.8%)
Top CVEs
Signals from CVEs in this product scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22732CRITICAL When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.
This issue affe | Mar 19, 2026 | 9.1 | 35 | NO | NO |
CVE-2022-22978CRITICAL In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet contain | May 19, 2022 | 9.8 | 34 | NO | NO |
CVE-2026-47838HIGH SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully | Jun 10, 2026 | 8.1 | 33 | NO | NO |
CVE-2023-34034CRITICAL Using "**" as a pattern in Spring Security configuration
for WebFlux creates a mismatch in pattern matching between Spring
Security and Spring WebFlux, and the potential for a se | Jul 19, 2023 | 9.8 | 33 | NO | NO |
CVE-2022-31692CRITICAL Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an app | Oct 31, 2022 | 9.8 | 33 | NO | NO |
CVE-2026-40988HIGH An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded wr | Jun 10, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-22754HIGH Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a | Apr 22, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-22747HIGH Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong | Apr 22, 2026 | 8.1 | 31 | NO | NO |
CVE-2014-3527CRITICAL When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was | May 25, 2017 | 9.8 | 30 | NO | NO |
CVE-2021-22112HIGH Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is chang | Feb 23, 2021 | 8.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (36 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (36 CVEs).
Media Mentions
Signals from CVEs in this product scope (36 CVEs).
Top CNAs Publishing CVEs For Spring Security
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.7.9 | 1 | 5.5 | 0.2% | 0 | 0 |
| 5.7.10 | 1 | 5.5 | 0.2% | 0 | 0 |
| 5.2.0 | 1 | 5.3 | 2.3% | 0 | 0 |
| 5.0.0 | 1 | 8.1 | 2.5% | 0 | 0 |
| 4.2.2 | 1 | 8.1 | 2.5% | 0 | 0 |
| 4.2.1 | 1 | 8.1 | 2.5% | 0 | 0 |
| 4.2.0 | 2 | 7.8 | 2.0% | 0 | 0 |
| 4.1.3 | 1 | 7.5 | 1.4% | 0 | 0 |
| 4.1.2 | 1 | 7.5 | 1.4% | 0 | 0 |
| 4.1.1 | 1 | 7.5 | 1.4% | 0 | 0 |
| 4.1.0 | 2 | 7.5 | 2.1% | 0 | 0 |
| 4.0.4 | 1 | 7.5 | 2.8% | 0 | 0 |
| 4.0.3 | 1 | 7.5 | 2.8% | 0 | 0 |
| 4.0.2 | 1 | 7.5 | 2.8% | 0 | 0 |
| 4.0.1 | 1 | 7.5 | 2.8% | 0 | 0 |
| 4.0.0 | 1 | 7.5 | 2.8% | 0 | 0 |
| 3.2.9 | 2 | 7.5 | 2.1% | 0 | 0 |
| 3.2.8 | 2 | 7.5 | 2.1% | 0 | 0 |
| 3.2.7 | 2 | 7.5 | 2.1% | 0 | 0 |
| 3.2.6 | 2 | 7.5 | 2.1% | 0 | 0 |