PT-2026-34252 · Spring · Spring Security
Published
2026-04-22
·
Updated
2026-04-22
·
CVE-2026-22748
CVSS v3.1
5.3
Medium
| AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N |
Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spring Security