// OSSeva Blog
SecuritySpring Security Vulnerabilities by Version: CVEs for Spring Security 5.7, 5.8, 6.x and 7.x
The short answer
Two Spring Security lines have open source support: 7.1 until 31 July 2027 and 7.0 until 31 December 2026. Their latest releases are 7.1.1 and 7.0.7, both from 20 August 2026. Open source support for 6.5 ended on 30 June 2026 with 6.5.11, and every older line is outside it. In 2026 spring.io has published 22 advisories against Spring Security. All of them have public fixes on 7.0 and 7.1. On 6.5, 9 of the 14 that name it have a public fix and 5 are fixed only in the commercial 6.5.12. On 6.4, 6.3, 5.8 and 5.7 every 2026 fix is marked Enterprise Support Only.
Spring Security usually arrives through Spring Boot, which pins it. Spring Boot 2.7.18 manages Spring Security 5.7.11, so a Boot 2.7 application that takes the managed version does not even have the last public 5.7 releases. For the Boot side, see Spring Boot vulnerabilities by version; for the framework underneath, Spring Framework vulnerabilities by version.
Spring Security release lines and their 2026 CVEs
Support dates are from the spring.io support generations for Spring Security, and the last public release is the newest version of each line on Maven Central. The counts are the 2026 spring.io advisories whose affected ranges include the line.
| Line | Open source support | Commercial support | Last public release | 2026 CVEs naming it | Upstream fix on this line |
|---|---|---|---|---|---|
| 7.1 | Until 31 July 2027 | Until 31 July 2028 | 7.1.1, 20 August 2026 | 7, including CVE-2026-59270 and CVE-2026-47841 | 7.1.1 has all of them |
| 7.0 | Until 31 December 2026 | Until 31 December 2027 | 7.0.7, 20 August 2026 | 20, including CVE-2026-59270, CVE-2026-59354 and CVE-2026-22732 | 7.0.7 has all of them |
| 6.5 | Ended 30 June 2026 | Until 30 June 2032 | 6.5.11, 9 June 2026 | 14, including CVE-2026-59270 and CVE-2026-22732 | 9 in 6.5.11; 5 only in the commercial 6.5.12 |
| 6.4 | Ended 31 December 2025 | Until 31 December 2026 | 6.4.13, 17 November 2025 | 13, including CVE-2026-59270 and CVE-2026-22732 | No public fix; all 13 Enterprise Support Only |
| 6.3 | Ended 30 June 2025 | Ended 30 June 2026 | 6.3.10 | 8, including CVE-2026-22732 and CVE-2026-40988 | No public fix; all 8 Enterprise Support Only |
| 6.0 to 6.2 | Ended | Ended; 6.2 on 31 December 2025 | 6.2.8; 6.1.9; 6.0.8 | Not assessed, except CVE-2026-22748, which names 6.1 and 6.2 | No upstream fix on these lines |
| 5.8 | Ended 31 December 2023 | Until 30 June 2029 | 5.8.16, November 2024 | 10, including CVE-2026-59270 and CVE-2026-22732 | No public fix; all 10 Enterprise Support Only |
| 5.7 | Ended 30 June 2023 | Until 30 June 2029 | 5.7.14, November 2024 | 10, the same as 5.8 | No public fix; all 10 Enterprise Support Only |
| 5.6 and older | Ended | Ended; 5.6 on 29 February 2024 | 5.6.12 | 7 advisories give 5.7 ranges as "and earlier" | No upstream fix on these lines |
"Not assessed" means the advisories stop at the lines Spring still sells support for. It is not a finding that 6.0 to 6.2 are safe, and the "and earlier" wording that seven advisories use for 5.7 reaches 5.6 and older. For the dates on every line, see the Spring Security end-of-life chart.
Notable Spring Security CVEs by release line
CVSS is NVD's own score where NVD has scored the record, otherwise VMware's score as the CNA. The two can differ widely: VMware scores CVE-2026-41003 7.6 where NVD gives 5.4, and CVE-2026-47838 6.8 where NVD gives 8.1. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.
| CVE | Issue | CVSS | Affected | Public fix | Enterprise Support Only fix |
|---|---|---|---|---|---|
| CVE-2026-59270 | The embedded UnboundID LDAP server registers a well-known admin bind DN and listens on all interfaces | 9.1 (NVD) | 5.7.0 to 5.7.25, 5.8.0 to 5.8.27, 6.4.0 to 6.4.18, 6.5.0 to 6.5.11, 7.0.0 to 7.0.6, 7.1.0 | 7.0.7, 7.1.1 | 5.7.26, 5.8.28, 6.4.19, 6.5.12 |
| CVE-2026-22732 | When a servlet application sets some response headers itself, lazy header writing, the default, can skip Spring Security's own headers | 9.1 (VMware) | 5.7.21 and earlier, 5.8.0 to 5.8.23, 6.3.0 to 6.3.14, 6.4.0 to 6.4.14, 6.5.0 to 6.5.8, 7.0.0 to 7.0.3 | 6.5.9, 7.0.4 | 5.7.22, 5.8.24, 6.3.15, 6.4.15 |
| CVE-2024-38821 | Authorization rules on static resources in WebFlux applications can be bypassed | 9.1 (VMware) | 5.7.12 and earlier, 5.8.0 to 5.8.14, 6.0.0 to 6.0.12, 6.1.0 to 6.1.10, 6.2.0 to 6.2.6, 6.3.0 to 6.3.3 | 6.2.7, 6.3.4 | 5.7.13, 5.8.15, 6.0.13, 6.1.11 |
| CVE-2025-41232 | With @EnableMethodSecurity(mode=ASPECTJ), annotations on private methods are not enforced | 9.1 (VMware) | 6.4.0 to 6.4.5 | 6.4.6 | None |
| CVE-2026-59354 | Authorization Server dynamic client registration accepts crafted client metadata, leading to stored XSS, privilege escalation or SSRF | 8.8 (NVD) | 7.0.0 to 7.0.4 | 7.0.5 | None |
| CVE-2024-22257 | AuthenticatedVoter#vote returns true when passed a null Authentication | 8.2 (VMware) | 5.7.11 and earlier, 5.8.0 to 5.8.10, 6.0.0 to 6.0.9, 6.1.0 to 6.1.7, 6.2.0 to 6.2.2 | 5.7.12, 5.8.11, 6.1.8, 6.2.3 | 6.0.10 |
| CVE-2026-47838 | SubjectDnX509PrincipalExtractor misreads a malformed certificate CN, so a crafted certificate can impersonate another user | 8.1 (NVD) | 5.7.24 and earlier, 5.8.0 to 5.8.26, 6.3.0 to 6.3.17, 6.4.0 to 6.4.17, 6.5.0 to 6.5.10 | 6.5.11 | 5.7.25, 5.8.27, 6.3.18, 6.4.18 |
| CVE-2026-22747 | The same flaw in SubjectX500PrincipalExtractor on 7.0 | 8.1 (NVD) | 7.0.0 to 7.0.4 | 7.0.5 | None |
| CVE-2026-22753 | securityMatchers(String) with a servlet path prefix can leave a filter chain unapplied | 7.5 (VMware) | 7.0.0 to 7.0.4 | 7.0.5 | None |
| CVE-2026-40988 | SAML 2.0 REDIRECT binding inflates compressed payloads without a limit | 7.5 (VMware) | 5.7.23 and earlier, 5.8.0 to 5.8.25, 6.3.0 to 6.3.16, 6.4.0 to 6.4.16, 6.5.0 to 6.5.10, 7.0.0 to 7.0.5 | 6.5.11, 7.0.6 | 5.7.24, 5.8.26, 6.3.17, 6.4.17 |
| CVE-2025-41248 | Method security annotations in generic superclasses or interfaces may not be found | 7.5 (VMware) | 6.4.0 to 6.4.10, 6.5.0 to 6.5.4 | 6.4.11, 6.5.5 | None |
| CVE-2025-22228 | BCryptPasswordEncoder.matches returns true for passwords over 72 characters whose first 72 match | 7.4 (VMware) | 5.7.15 and earlier, 5.8.0 to 5.8.17, 6.0.0 to 6.0.15, 6.1.0 to 6.1.13, 6.2.0 to 6.2.9, 6.3.0 to 6.3.7, 6.4.0 to 6.4.3 | 6.3.8, 6.4.4 | 5.7.16, 5.8.18, 6.0.16, 6.1.14, 6.2.10 |
| CVE-2026-41707 | Flooding the DPoP replay cache evicts a proof's JWT ID so an intercepted proof can be replayed | 7.4 (VMware) | 6.5.0 to 6.5.11, 7.0.0 to 7.0.6, 7.1.0 | 7.0.7, 7.1.1 | 6.5.12 |
| CVE-2026-47841 | WebAuthn user verification is skipped after a session is serialized to a distributed store | 7.4 (VMware) | 6.4.0 to 6.4.18, 6.5.0 to 6.5.11, 7.0.0 to 7.0.6, 7.1.0 | 7.0.7, 7.1.1 | 6.4.19, 6.5.12 |
| CVE-2026-40993 | JdbcAssertingPartyMetadataRepository deserializes credential columns, so a database writer can run code | 7.2 (NVD) | 7.0.0 to 7.0.5 | 7.0.6 | 7.0.5.1 |
| CVE-2026-47842 | AesBytesEncryptor in CBC mode with no IV generator uses an all-zero IV, so equal plaintexts give equal ciphertexts | 6.5 (VMware) | 5.7.0 to 5.7.25, 5.8.0 to 5.8.27, 6.4.0 to 6.4.18, 6.5.0 to 6.5.11, 7.0.0 to 7.0.6, 7.1.0 | 7.0.7, 7.1.1 | 5.7.26, 5.8.28, 6.4.19, 6.5.12 |
Almost every row needs a particular feature to be in use, and each advisory says which. CVE-2026-59270 needs the embedded UnboundID server, configured directly or through Spring Boot's spring.ldap.embedded properties. CVE-2026-22732 matters to servlet applications that set some response headers themselves. The others need SAML 2.0 login, X.509 pre-authentication, WebAuthn, DPoP, AspectJ method security or the Authorization Server. Listing the Spring Security modules on the classpath, and the features configured in each SecurityFilterChain, tells you which rows apply.
The Authorization Server rows are new territory. Spring Authorization Server used to be a separate project, and from 7.0 its code ships inside Spring Security, which is why CVE-2026-59354 is a Spring Security CVE. The separate project's 1.3 to 1.5 lines had their own critical advisory in 2026, CVE-2026-22752, fixed publicly in 1.5.7.
What each line gets
Spring Security 7.0 and 7.1
7.1.1 and 7.0.7 carry every 2026 fix that applies to them. 7.0 leaves open source support on 31 December 2026, so applications on Spring Boot 4.0 should plan the move to 7.1 with Boot 4.1. See Spring Security 7.0 end of life.
Spring Security 6.5
6.5 is the last 6.x line, and the one Spring Boot 3.5.16 manages. Its final public release, 6.5.11, has 9 of the 14 fixes from 2026 that apply to it. The other 5, from August 2026 and including CVE-2026-59270 and CVE-2026-47841, are fixed in 6.5.12, which is Enterprise Support Only. Commercial support for 6.5 runs to 30 June 2032, so further 6.5 fixes will keep arriving, but not publicly. See Spring Security 6 end of life.
Spring Security 6.4 and 6.3
6.4.13 and 6.3.10 are the last public releases, and none of the 2026 fixes for these lines is public. Commercial support for 6.3 ended on 30 June 2026. The June 2026 commercial releases 6.3.17 and 6.3.18 are the last 6.3 fixes the advisories list, and CVE-2026-59270 and the other August 2026 CVEs do not list 6.3 at all.
Spring Security 6.0 to 6.2
Commercial support for 6.2 ended on 31 December 2025, for 6.1 on 30 June 2025 and for 6.0 on 31 December 2024. 6.2.8, 6.1.9 and 6.0.8 lack every fix since, including CVE-2025-22228, and 6.1.9 and 6.0.8 also lack the fix for CVE-2024-38821. The 2026 advisories mostly do not assess these lines. These are the versions managed by Spring Boot 3.2, 3.1 and 3.0.
Spring Security 5.8 and 5.7
The newest 5.8 and 5.7 releases on Maven Central are 5.8.16 and 5.7.14, both from November 2024, and they carry the fixes for CVE-2024-38821 and CVE-2024-38827. Nothing from 2025 or 2026 is public on either line, though spring.io lists commercial support for both until 30 June 2029. 5.8 was released to prepare applications for 6.0, so the usual next step is the Spring Security 5.8 to 6.x migration. Spring Boot 2.7.18 manages 5.7.11, which is older than the last public 5.7 release, so Boot 2.7 applications lack even CVE-2024-22257's public fix in 5.7.12 unless they override spring-security.version. See Spring Security 5.8 end of life.
What to do on each line
- 7.0 and 7.1. Stay on 7.0.7 or 7.1.1 or later, and plan the move off 7.0 before 31 December 2026.
- 6.5. Move to 7.0 or 7.1, which means Spring Boot 4, or take patched builds. If you use the embedded LDAP server outside tests, make sure its port is reachable only from the local host, for CVE-2026-59270.
- 6.0 to 6.4. Move to 6.5.11 as a step if 7.x is far off, since 6.5.11 carries more public fixes than any older 6.x release, then plan the major upgrade.
- 5.7 and 5.8. At minimum, override Spring Boot's managed version to 5.7.14 or 5.8.16. Then migrate to 6.x, or take patched builds from a supplier that backports fixes. Until then, set HeaderWriterFilter's shouldWriteHeadersEagerly to true, which is the workaround the CVE-2026-22732 advisory gives, and check for passwords longer than 72 characters if you use BCrypt.
Where OSSeva fits
OSSeva backports Spring Security fixes to the 5.6, 5.7 and 5.8 lines and to the 6.0 to 6.5 lines, delivered as GPG-signed Maven artifacts, with emergency patches for authentication bypass CVEs. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a Spring Security configuration audit, an OAuth 2.0 and OIDC configuration review and a Spring Security 6 migration assessment, and Operate adds 24/7 authentication event monitoring with a 15-minute P1 response for authentication bypass incidents and a named senior Spring Security engineer. See Spring Security support and Spring Security extended support past EOL.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.