Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-22753

Spring Security: securityMatchers(String) with a servlet path prefix can leave a filter chain unapplied

Technology

Spring Security

CVSS Score

7.5 / 10.0

Affected Versions

7.0.0 to 7.0.4

Upstream Fix

7.0.5

Published

April 22, 2026

OSSeva Coverage

Fixed upstream

Description

When an application uses securityMatchers(String) together with a PathPatternRequestMatcher.Builder bean that prepends a servlet path, requests may fail to match the filter chain, so its authentication and authorization controls are not applied. For Spring Boot applications, the advisory suggests checking whether spring.mvc.servlet.path is set. Spring Security 6.x and earlier are not affected. The 7.5 score is VMware's as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 7.0.0 to 7.0.4, you need this patch. Book a discovery call to get covered.