Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-47842

Spring Security: AesBytesEncryptor in CBC mode uses an all-zero IV

Technology

Spring Security

CVSS Score

6.5 / 10.0

Affected Versions

5.7.0 to 5.7.25; 5.8.0 to 5.8.27; 6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0

Upstream Fix

7.0.7; 7.1.1; 7.0.6.1, 7.1.0.1, 6.5.12, 6.4.19, 5.8.28, 5.7.26 (Enterprise Support Only)

Published

August 26, 2026

OSSeva Coverage

Fixed upstream

Description

AesBytesEncryptor created with the two-argument constructor, or with CBC mode and a null IV generator, encrypts with a fixed all-zero initialization vector, so identical plaintexts give identical ciphertexts for a given password and salt. An attacker with read access to the encrypted data can correlate records and mount dictionary attacks. The fix deprecates AesBytesEncryptor in favour of AesCbcBytesEncryptor and AesGcmBytesEncryptor, and existing data may need re-encryption. It continues CVE-2020-5408. The 6.5 score is VMware's as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Security deployment affected?

If you're running 5.7.0 to 5.7.25; 5.8.0 to 5.8.27; 6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0, you need this patch. Book a discovery call to get covered.