CVE-2026-47838
Spring Security: SubjectDnX509PrincipalExtractor misreads malformed certificate CNs
Technology
Spring Security
CVSS Score
8.1 / 10.0
Affected Versions
5.7.24 and earlier; 5.8.0 to 5.8.26; 6.3.0 to 6.3.17; 6.4.0 to 6.4.17; 6.5.0 to 6.5.10
Upstream Fix
6.5.11; 6.5.10.2, 6.4.18, 6.3.18, 5.8.27, 5.7.25 (Enterprise Support Only)
Published
June 10, 2026
OSSeva Coverage
Fixed upstream
Description
SubjectDnX509PrincipalExtractor does not correctly handle some malformed X.509 certificate CN values and can read the wrong username, so a carefully crafted certificate can impersonate another user. It continues CVE-2026-22747 for the 6.x and 5.x lines. The advisory notes that the component sits behind pre-authentication that trusts an upstream validator, and deprecates the class in favour of SubjectX500PrincipalExtractor. VMware scores it 6.8 as the CNA.
Is your Spring Security deployment affected?
If you're running 5.7.24 and earlier; 5.8.0 to 5.8.26; 6.3.0 to 6.3.17; 6.4.0 to 6.4.17; 6.5.0 to 6.5.10, you need this patch. Book a discovery call to get covered.