Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-40988

Spring Security SAML 2.0: REDIRECT binding inflates compressed payloads without a limit

Technology

Spring Security

CVSS Score

7.5 / 10.0

Affected Versions

5.7.23 and earlier; 5.8.0 to 5.8.25; 6.3.0 to 6.3.16; 6.4.0 to 6.4.16; 6.5.0 to 6.5.10; 7.0.0 to 7.0.5

Upstream Fix

6.5.11; 7.0.6; 7.0.5.1, 6.5.10.2, 6.4.17, 6.3.17, 5.8.26, 5.7.24 (Enterprise Support Only)

Published

June 10, 2026

OSSeva Coverage

Fixed upstream

Description

An application using spring-security-saml2-service-provider with the REDIRECT binding for SAML 2.0 login or logout can be made to inflate a compressed SAML payload into memory without a bound, causing denial of service. The 7.5 score is VMware's as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 5.7.23 and earlier; 5.8.0 to 5.8.25; 6.3.0 to 6.3.16; 6.4.0 to 6.4.16; 6.5.0 to 6.5.10; 7.0.0 to 7.0.5, you need this patch. Book a discovery call to get covered.