Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-47838

Spring Security: SubjectDnX509PrincipalExtractor misreads malformed certificate CNs

Technology

Spring Security

CVSS Score

8.1 / 10.0

Affected Versions

5.7.24 and earlier; 5.8.0 to 5.8.26; 6.3.0 to 6.3.17; 6.4.0 to 6.4.17; 6.5.0 to 6.5.10

Upstream Fix

6.5.11; 6.5.10.2, 6.4.18, 6.3.18, 5.8.27, 5.7.25 (Enterprise Support Only)

Published

June 10, 2026

OSSeva Coverage

Fixed upstream

Description

SubjectDnX509PrincipalExtractor does not correctly handle some malformed X.509 certificate CN values and can read the wrong username, so a carefully crafted certificate can impersonate another user. It continues CVE-2026-22747 for the 6.x and 5.x lines. The advisory notes that the component sits behind pre-authentication that trusts an upstream validator, and deprecates the class in favour of SubjectX500PrincipalExtractor. VMware scores it 6.8 as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 5.7.24 and earlier; 5.8.0 to 5.8.26; 6.3.0 to 6.3.17; 6.4.0 to 6.4.17; 6.5.0 to 6.5.10, you need this patch. Book a discovery call to get covered.