Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-22747

Spring Security: SubjectX500PrincipalExtractor misreads malformed certificate CNs

Technology

Spring Security

CVSS Score

8.1 / 10.0

Affected Versions

7.0.0 to 7.0.4

Upstream Fix

7.0.5

Published

April 22, 2026

OSSeva Coverage

Fixed upstream

Description

SubjectX500PrincipalExtractor does not correctly handle some malformed X.509 certificate CN values and can read the wrong username, so a carefully crafted certificate can impersonate another user. The advisory describes the fix as defence in depth, since the component sits behind pre-authentication that trusts an upstream validator. VMware scores it 6.8 as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 7.0.0 to 7.0.4, you need this patch. Book a discovery call to get covered.