Spring Security
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Spring Security.
By the Year
In 2026 there have been 1 vulnerability in Spring Security with an average score of 7.4 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 7.40 |
It may take a day or so for new Spring Security vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Spring Security Security Vulnerabilities
Spring Security 7.x DPoPProofJwtDecoderFactory Replay Attack via Cache Eviction
CVE-2026-41707
7.4 - High
- August 25, 2026
Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. This issue affects Spring Security: 7.1.0, from 7.0.0 through 7.0.6, and from 6.5.0 through 6.5.11.
Authentication Bypass by Capture-replay
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Spring Security or by Spring? Click the Watch button to subscribe.