Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-40988
Spring Security SAML 2.0: REDIRECT binding inflates compressed payloads without a limit
Technology
Spring Security
CVSS Score
7.5 / 10.0
Affected Versions
5.7.23 and earlier; 5.8.0 to 5.8.25; 6.3.0 to 6.3.16; 6.4.0 to 6.4.16; 6.5.0 to 6.5.10; 7.0.0 to 7.0.5
Upstream Fix
6.5.11; 7.0.6; 7.0.5.1, 6.5.10.2, 6.4.17, 6.3.17, 5.8.26, 5.7.24 (Enterprise Support Only)
Published
June 10, 2026
OSSeva Coverage
Fixed upstream
Is your Spring Security deployment affected?
If you're running 5.7.23 and earlier; 5.8.0 to 5.8.25; 6.3.0 to 6.3.16; 6.4.0 to 6.4.16; 6.5.0 to 6.5.10; 7.0.0 to 7.0.5, you need this patch. Book a discovery call to get covered.