Back to blog

// OSSeva Blog

Security

Spring Security Vulnerabilities by Version: CVEs for Spring Security 5.7, 5.8, 6.x and 7.x

Randall McClure10 min read

The short answer

Two Spring Security lines have open source support: 7.1 until 31 July 2027 and 7.0 until 31 December 2026. Their latest releases are 7.1.1 and 7.0.7, both from 20 August 2026. Open source support for 6.5 ended on 30 June 2026 with 6.5.11, and every older line is outside it. In 2026 spring.io has published 22 advisories against Spring Security. All of them have public fixes on 7.0 and 7.1. On 6.5, 9 of the 14 that name it have a public fix and 5 are fixed only in the commercial 6.5.12. On 6.4, 6.3, 5.8 and 5.7 every 2026 fix is marked Enterprise Support Only.

Spring Security usually arrives through Spring Boot, which pins it. Spring Boot 2.7.18 manages Spring Security 5.7.11, so a Boot 2.7 application that takes the managed version does not even have the last public 5.7 releases. For the Boot side, see Spring Boot vulnerabilities by version; for the framework underneath, Spring Framework vulnerabilities by version.

Spring Security release lines and their 2026 CVEs

Support dates are from the spring.io support generations for Spring Security, and the last public release is the newest version of each line on Maven Central. The counts are the 2026 spring.io advisories whose affected ranges include the line.

LineOpen source supportCommercial supportLast public release2026 CVEs naming itUpstream fix on this line
7.1Until 31 July 2027Until 31 July 20287.1.1, 20 August 20267, including CVE-2026-59270 and CVE-2026-478417.1.1 has all of them
7.0Until 31 December 2026Until 31 December 20277.0.7, 20 August 202620, including CVE-2026-59270, CVE-2026-59354 and CVE-2026-227327.0.7 has all of them
6.5Ended 30 June 2026Until 30 June 20326.5.11, 9 June 202614, including CVE-2026-59270 and CVE-2026-227329 in 6.5.11; 5 only in the commercial 6.5.12
6.4Ended 31 December 2025Until 31 December 20266.4.13, 17 November 202513, including CVE-2026-59270 and CVE-2026-22732No public fix; all 13 Enterprise Support Only
6.3Ended 30 June 2025Ended 30 June 20266.3.108, including CVE-2026-22732 and CVE-2026-40988No public fix; all 8 Enterprise Support Only
6.0 to 6.2EndedEnded; 6.2 on 31 December 20256.2.8; 6.1.9; 6.0.8Not assessed, except CVE-2026-22748, which names 6.1 and 6.2No upstream fix on these lines
5.8Ended 31 December 2023Until 30 June 20295.8.16, November 202410, including CVE-2026-59270 and CVE-2026-22732No public fix; all 10 Enterprise Support Only
5.7Ended 30 June 2023Until 30 June 20295.7.14, November 202410, the same as 5.8No public fix; all 10 Enterprise Support Only
5.6 and olderEndedEnded; 5.6 on 29 February 20245.6.127 advisories give 5.7 ranges as "and earlier"No upstream fix on these lines

"Not assessed" means the advisories stop at the lines Spring still sells support for. It is not a finding that 6.0 to 6.2 are safe, and the "and earlier" wording that seven advisories use for 5.7 reaches 5.6 and older. For the dates on every line, see the Spring Security end-of-life chart.

Notable Spring Security CVEs by release line

CVSS is NVD's own score where NVD has scored the record, otherwise VMware's score as the CNA. The two can differ widely: VMware scores CVE-2026-41003 7.6 where NVD gives 5.4, and CVE-2026-47838 6.8 where NVD gives 8.1. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.

CVEIssueCVSSAffectedPublic fixEnterprise Support Only fix
CVE-2026-59270The embedded UnboundID LDAP server registers a well-known admin bind DN and listens on all interfaces9.1 (NVD)5.7.0 to 5.7.25, 5.8.0 to 5.8.27, 6.4.0 to 6.4.18, 6.5.0 to 6.5.11, 7.0.0 to 7.0.6, 7.1.07.0.7, 7.1.15.7.26, 5.8.28, 6.4.19, 6.5.12
CVE-2026-22732When a servlet application sets some response headers itself, lazy header writing, the default, can skip Spring Security's own headers9.1 (VMware)5.7.21 and earlier, 5.8.0 to 5.8.23, 6.3.0 to 6.3.14, 6.4.0 to 6.4.14, 6.5.0 to 6.5.8, 7.0.0 to 7.0.36.5.9, 7.0.45.7.22, 5.8.24, 6.3.15, 6.4.15
CVE-2024-38821Authorization rules on static resources in WebFlux applications can be bypassed9.1 (VMware)5.7.12 and earlier, 5.8.0 to 5.8.14, 6.0.0 to 6.0.12, 6.1.0 to 6.1.10, 6.2.0 to 6.2.6, 6.3.0 to 6.3.36.2.7, 6.3.45.7.13, 5.8.15, 6.0.13, 6.1.11
CVE-2025-41232With @EnableMethodSecurity(mode=ASPECTJ), annotations on private methods are not enforced9.1 (VMware)6.4.0 to 6.4.56.4.6None
CVE-2026-59354Authorization Server dynamic client registration accepts crafted client metadata, leading to stored XSS, privilege escalation or SSRF8.8 (NVD)7.0.0 to 7.0.47.0.5None
CVE-2024-22257AuthenticatedVoter#vote returns true when passed a null Authentication8.2 (VMware)5.7.11 and earlier, 5.8.0 to 5.8.10, 6.0.0 to 6.0.9, 6.1.0 to 6.1.7, 6.2.0 to 6.2.25.7.12, 5.8.11, 6.1.8, 6.2.36.0.10
CVE-2026-47838SubjectDnX509PrincipalExtractor misreads a malformed certificate CN, so a crafted certificate can impersonate another user8.1 (NVD)5.7.24 and earlier, 5.8.0 to 5.8.26, 6.3.0 to 6.3.17, 6.4.0 to 6.4.17, 6.5.0 to 6.5.106.5.115.7.25, 5.8.27, 6.3.18, 6.4.18
CVE-2026-22747The same flaw in SubjectX500PrincipalExtractor on 7.08.1 (NVD)7.0.0 to 7.0.47.0.5None
CVE-2026-22753securityMatchers(String) with a servlet path prefix can leave a filter chain unapplied7.5 (VMware)7.0.0 to 7.0.47.0.5None
CVE-2026-40988SAML 2.0 REDIRECT binding inflates compressed payloads without a limit7.5 (VMware)5.7.23 and earlier, 5.8.0 to 5.8.25, 6.3.0 to 6.3.16, 6.4.0 to 6.4.16, 6.5.0 to 6.5.10, 7.0.0 to 7.0.56.5.11, 7.0.65.7.24, 5.8.26, 6.3.17, 6.4.17
CVE-2025-41248Method security annotations in generic superclasses or interfaces may not be found7.5 (VMware)6.4.0 to 6.4.10, 6.5.0 to 6.5.46.4.11, 6.5.5None
CVE-2025-22228BCryptPasswordEncoder.matches returns true for passwords over 72 characters whose first 72 match7.4 (VMware)5.7.15 and earlier, 5.8.0 to 5.8.17, 6.0.0 to 6.0.15, 6.1.0 to 6.1.13, 6.2.0 to 6.2.9, 6.3.0 to 6.3.7, 6.4.0 to 6.4.36.3.8, 6.4.45.7.16, 5.8.18, 6.0.16, 6.1.14, 6.2.10
CVE-2026-41707Flooding the DPoP replay cache evicts a proof's JWT ID so an intercepted proof can be replayed7.4 (VMware)6.5.0 to 6.5.11, 7.0.0 to 7.0.6, 7.1.07.0.7, 7.1.16.5.12
CVE-2026-47841WebAuthn user verification is skipped after a session is serialized to a distributed store7.4 (VMware)6.4.0 to 6.4.18, 6.5.0 to 6.5.11, 7.0.0 to 7.0.6, 7.1.07.0.7, 7.1.16.4.19, 6.5.12
CVE-2026-40993JdbcAssertingPartyMetadataRepository deserializes credential columns, so a database writer can run code7.2 (NVD)7.0.0 to 7.0.57.0.67.0.5.1
CVE-2026-47842AesBytesEncryptor in CBC mode with no IV generator uses an all-zero IV, so equal plaintexts give equal ciphertexts6.5 (VMware)5.7.0 to 5.7.25, 5.8.0 to 5.8.27, 6.4.0 to 6.4.18, 6.5.0 to 6.5.11, 7.0.0 to 7.0.6, 7.1.07.0.7, 7.1.15.7.26, 5.8.28, 6.4.19, 6.5.12

Almost every row needs a particular feature to be in use, and each advisory says which. CVE-2026-59270 needs the embedded UnboundID server, configured directly or through Spring Boot's spring.ldap.embedded properties. CVE-2026-22732 matters to servlet applications that set some response headers themselves. The others need SAML 2.0 login, X.509 pre-authentication, WebAuthn, DPoP, AspectJ method security or the Authorization Server. Listing the Spring Security modules on the classpath, and the features configured in each SecurityFilterChain, tells you which rows apply.

The Authorization Server rows are new territory. Spring Authorization Server used to be a separate project, and from 7.0 its code ships inside Spring Security, which is why CVE-2026-59354 is a Spring Security CVE. The separate project's 1.3 to 1.5 lines had their own critical advisory in 2026, CVE-2026-22752, fixed publicly in 1.5.7.

What each line gets

Spring Security 7.0 and 7.1

7.1.1 and 7.0.7 carry every 2026 fix that applies to them. 7.0 leaves open source support on 31 December 2026, so applications on Spring Boot 4.0 should plan the move to 7.1 with Boot 4.1. See Spring Security 7.0 end of life.

Spring Security 6.5

6.5 is the last 6.x line, and the one Spring Boot 3.5.16 manages. Its final public release, 6.5.11, has 9 of the 14 fixes from 2026 that apply to it. The other 5, from August 2026 and including CVE-2026-59270 and CVE-2026-47841, are fixed in 6.5.12, which is Enterprise Support Only. Commercial support for 6.5 runs to 30 June 2032, so further 6.5 fixes will keep arriving, but not publicly. See Spring Security 6 end of life.

Spring Security 6.4 and 6.3

6.4.13 and 6.3.10 are the last public releases, and none of the 2026 fixes for these lines is public. Commercial support for 6.3 ended on 30 June 2026. The June 2026 commercial releases 6.3.17 and 6.3.18 are the last 6.3 fixes the advisories list, and CVE-2026-59270 and the other August 2026 CVEs do not list 6.3 at all.

Spring Security 6.0 to 6.2

Commercial support for 6.2 ended on 31 December 2025, for 6.1 on 30 June 2025 and for 6.0 on 31 December 2024. 6.2.8, 6.1.9 and 6.0.8 lack every fix since, including CVE-2025-22228, and 6.1.9 and 6.0.8 also lack the fix for CVE-2024-38821. The 2026 advisories mostly do not assess these lines. These are the versions managed by Spring Boot 3.2, 3.1 and 3.0.

Spring Security 5.8 and 5.7

The newest 5.8 and 5.7 releases on Maven Central are 5.8.16 and 5.7.14, both from November 2024, and they carry the fixes for CVE-2024-38821 and CVE-2024-38827. Nothing from 2025 or 2026 is public on either line, though spring.io lists commercial support for both until 30 June 2029. 5.8 was released to prepare applications for 6.0, so the usual next step is the Spring Security 5.8 to 6.x migration. Spring Boot 2.7.18 manages 5.7.11, which is older than the last public 5.7 release, so Boot 2.7 applications lack even CVE-2024-22257's public fix in 5.7.12 unless they override spring-security.version. See Spring Security 5.8 end of life.

What to do on each line

  • 7.0 and 7.1. Stay on 7.0.7 or 7.1.1 or later, and plan the move off 7.0 before 31 December 2026.
  • 6.5. Move to 7.0 or 7.1, which means Spring Boot 4, or take patched builds. If you use the embedded LDAP server outside tests, make sure its port is reachable only from the local host, for CVE-2026-59270.
  • 6.0 to 6.4. Move to 6.5.11 as a step if 7.x is far off, since 6.5.11 carries more public fixes than any older 6.x release, then plan the major upgrade.
  • 5.7 and 5.8. At minimum, override Spring Boot's managed version to 5.7.14 or 5.8.16. Then migrate to 6.x, or take patched builds from a supplier that backports fixes. Until then, set HeaderWriterFilter's shouldWriteHeadersEagerly to true, which is the workaround the CVE-2026-22732 advisory gives, and check for passwords longer than 72 characters if you use BCrypt.

Where OSSeva fits

OSSeva backports Spring Security fixes to the 5.6, 5.7 and 5.8 lines and to the 6.0 to 6.5 lines, delivered as GPG-signed Maven artifacts, with emergency patches for authentication bypass CVEs. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a Spring Security configuration audit, an OAuth 2.0 and OIDC configuration review and a Spring Security 6 migration assessment, and Operate adds 24/7 authentication event monitoring with a 15-minute P1 response for authentication bypass incidents and a named senior Spring Security engineer. See Spring Security support and Spring Security extended support past EOL.

Tags

Spring SecurityCVESpring Security 5.8Spring Security 6End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.