CVE-2026-47842
Spring Security: AesBytesEncryptor in CBC mode uses an all-zero IV
Technology
Spring Security
CVSS Score
6.5 / 10.0
Affected Versions
5.7.0 to 5.7.25; 5.8.0 to 5.8.27; 6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0
Upstream Fix
7.0.7; 7.1.1; 7.0.6.1, 7.1.0.1, 6.5.12, 6.4.19, 5.8.28, 5.7.26 (Enterprise Support Only)
Published
August 26, 2026
OSSeva Coverage
Fixed upstream
Description
AesBytesEncryptor created with the two-argument constructor, or with CBC mode and a null IV generator, encrypts with a fixed all-zero initialization vector, so identical plaintexts give identical ciphertexts for a given password and salt. An attacker with read access to the encrypted data can correlate records and mount dictionary attacks. The fix deprecates AesBytesEncryptor in favour of AesCbcBytesEncryptor and AesGcmBytesEncryptor, and existing data may need re-encryption. It continues CVE-2020-5408. The 6.5 score is VMware's as the CNA.
Is your Spring Security deployment affected?
If you're running 5.7.0 to 5.7.25; 5.8.0 to 5.8.27; 6.4.0 to 6.4.18; 6.5.0 to 6.5.11; 7.0.0 to 7.0.6; 7.1.0, you need this patch. Book a discovery call to get covered.