Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-41707

Spring Security: DPoP proof replay after forced cache eviction

Technology

Spring Security

CVSS Score

7.4 / 10.0

Affected Versions

6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0

Upstream Fix

7.0.7; 7.1.1; 7.0.6.1, 7.1.0.1, 6.5.12 (Enterprise Support Only)

Published

August 25, 2026

OSSeva Coverage

Fixed upstream

Description

DPoPProofJwtDecoderFactory keeps processed JWT ID claims in a size-limited cache to stop DPoP proofs being replayed. An attacker who intercepts a valid proof can flood the server with requests to evict its JWT ID and then replay the proof, impersonating the victim. The 7.4 score is VMware's as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0, you need this patch. Book a discovery call to get covered.