CVE-2026-22732
Spring Security: HTTP security headers may not be written in servlet applications
Technology
Spring Security
CVSS Score
9.1 / 10.0
Affected Versions
5.7.21 and earlier; 5.8.0 to 5.8.23; 6.3.0 to 6.3.14; 6.4.0 to 6.4.14; 6.5.0 to 6.5.8; 7.0.0 to 7.0.3
Upstream Fix
6.5.9; 7.0.4; 6.4.15, 6.3.15, 5.8.24, 5.7.22 (Enterprise Support Only)
Published
March 19, 2026
OSSeva Coverage
Fixed upstream
Description
In servlet applications using lazy writing of HTTP headers, the default, Spring Security may not write its security headers when the application sets some response headers itself; for example, if the application sets any cache-related header, Spring Security writes none. This can expose sensitive data through caching. The advisory's workaround is to set HeaderWriterFilter's shouldWriteHeadersEagerly property to true. The 9.1 score is VMware's as the CNA.
Is your Spring Security deployment affected?
If you're running 5.7.21 and earlier; 5.8.0 to 5.8.23; 6.3.0 to 6.3.14; 6.4.0 to 6.4.14; 6.5.0 to 6.5.8; 7.0.0 to 7.0.3, you need this patch. Book a discovery call to get covered.