Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-41707
Spring Security: DPoP proof replay after forced cache eviction
Technology
Spring Security
CVSS Score
7.4 / 10.0
Affected Versions
6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0
Upstream Fix
7.0.7; 7.1.1; 7.0.6.1, 7.1.0.1, 6.5.12 (Enterprise Support Only)
Published
August 25, 2026
OSSeva Coverage
Fixed upstream
Description
DPoPProofJwtDecoderFactory keeps processed JWT ID claims in a size-limited cache to stop DPoP proofs being replayed. An attacker who intercepts a valid proof can flood the server with requests to evict its JWT ID and then replay the proof, impersonating the victim. The 7.4 score is VMware's as the CNA.
Is your Spring Security deployment affected?
If you're running 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0, you need this patch. Book a discovery call to get covered.