PT-2026-26435 · Vmware · Spring Security

Wyfrel

·

Published

2026-03-19

·

Updated

2026-05-18

·

CVE-2026-22732

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spring Security versions 5.7.0 through 5.7.21 Spring Security versions 5.8.0 through 5.8.23 Spring Security versions 6.3.0 through 6.3.14 Spring Security versions 6.4.0 through 6.4.14 Spring Security versions 6.5.0 through 6.5.8 Spring Security versions 7.0.0 through 7.0.3
Description In servlet applications using lazy (default) writing of HTTP headers, there is a possibility that specified HTTP response headers will not be written. This can lead to security headers being silently dropped without errors or logs, potentially exposing applications to data leaks. Additionally, some reports indicate the issue may be related to an insecure direct object reference that could allow a remote attacker to execute arbitrary code via a specially crafted HTTP request.
Recommendations Update versions 5.7.0 through 5.7.21 to a version later than 5.7.21. Update versions 5.8.0 through 5.8.23 to a version later than 5.8.23. Update versions 6.3.0 through 6.3.14 to a version later than 6.3.14. Update versions 6.4.0 through 6.4.14 to a version later than 6.4.14. Update versions 6.5.0 through 6.5.8 to a version later than 6.5.8. Update versions 7.0.0 through 7.0.3 to a version later than 7.0.3.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-03480
CLEANSTART-2026-AV84730
CLEANSTART-2026-DY69070
CLEANSTART-2026-GN46454
CLEANSTART-2026-KB76878
CLEANSTART-2026-SR31778
CLEANSTART-2026-TK07726
CLEANSTART-2026-VN28553
CVE-2026-22732
GHSA-MF92-479X-3373

Affected Products

Spring Security