CVE-2026-22753
Spring Security: securityMatchers(String) with a servlet path prefix can leave a filter chain unapplied
Technology
Spring Security
CVSS Score
7.5 / 10.0
Affected Versions
7.0.0 to 7.0.4
Upstream Fix
7.0.5
Published
April 22, 2026
OSSeva Coverage
Fixed upstream
Description
When an application uses securityMatchers(String) together with a PathPatternRequestMatcher.Builder bean that prepends a servlet path, requests may fail to match the filter chain, so its authentication and authorization controls are not applied. For Spring Boot applications, the advisory suggests checking whether spring.mvc.servlet.path is set. Spring Security 6.x and earlier are not affected. The 7.5 score is VMware's as the CNA.
Is your Spring Security deployment affected?
If you're running 7.0.0 to 7.0.4, you need this patch. Book a discovery call to get covered.