Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-22732

Spring Security: HTTP security headers may not be written in servlet applications

Technology

Spring Security

CVSS Score

9.1 / 10.0

Affected Versions

5.7.21 and earlier; 5.8.0 to 5.8.23; 6.3.0 to 6.3.14; 6.4.0 to 6.4.14; 6.5.0 to 6.5.8; 7.0.0 to 7.0.3

Upstream Fix

6.5.9; 7.0.4; 6.4.15, 6.3.15, 5.8.24, 5.7.22 (Enterprise Support Only)

Published

March 19, 2026

OSSeva Coverage

Fixed upstream

Description

In servlet applications using lazy writing of HTTP headers, the default, Spring Security may not write its security headers when the application sets some response headers itself; for example, if the application sets any cache-related header, Spring Security writes none. This can expose sensitive data through caching. The advisory's workaround is to set HeaderWriterFilter's shouldWriteHeadersEagerly property to true. The 9.1 score is VMware's as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 5.7.21 and earlier; 5.8.0 to 5.8.23; 6.3.0 to 6.3.14; 6.4.0 to 6.4.14; 6.5.0 to 6.5.8; 7.0.0 to 7.0.3, you need this patch. Book a discovery call to get covered.