Spring Security Spring Security

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Spring Security.

By the Year

In 2026 there have been 1 vulnerability in Spring Security with an average score of 7.4 out of ten.

Year Vulnerabilities Average Score
2026 1 7.40

It may take a day or so for new Spring Security vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Spring Security Security Vulnerabilities

Spring Security 7.x DPoPProofJwtDecoderFactory Replay Attack via Cache Eviction
CVE-2026-41707 7.4 - High - August 25, 2026

Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. This issue affects Spring Security: 7.1.0, from 7.0.0 through 7.0.6, and from 6.5.0 through 6.5.11.

Authentication Bypass by Capture-replay

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Spring Security or by Spring? Click the Watch button to subscribe.

Spring
Vendor

subscribe