← Vulnerability feed

Vulnerability record · CVE-2022-22969 · published 21 April 2022

CVE-2022-22969: Pivotal spring security oauth vulnerability

Pivotal · Spring Security Oauth

<Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session. This vulnerability exposes OAuth 2.0 Client applications only.

6.5 CVSS 3.1 Medium EPSS 1.3% · top 31.7%
6.5CVSS 3.1 base score, v2 4.0
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

<Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Request in an OAuth 2.0 Client application. A malicious user or attacker can send multiple requests initiating the Authorization Request for the Authorization Code Grant, which has the potential of exhausting system resources using a single session. This vulnerability exposes OAuth 2.0 Client applications only.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22969 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-4977Spring Security OAuth whitelabel views SpEL injection enables RCESpring Security OAuth versions 2.0.0-2.0.9 and 1.0.0-1.0.5 execute the response_type parameter as Spring Expression Language (SpEL) when processing a…EPSS 79%analysed8.3CVE-2021-2351Oracle advanced networking option broken cryptographic algorithm vulnerabilityVulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and …EPSS 2.4%7.5CVE-2020-11612Netty allocation without limits vulnerabilityThe ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send …EPSS 9.2%7.5CVE-2019-0227Apache Axis 1.4 SSRF via AdminService (expired domain)Apache Axis 1.4, last released in 2006, contains a server-side request forgery flaw in its AdminService. The service can be induced to fetch a remote…EPSS 92%analysed7.3CVE-2019-10086Apache commons beanutils deserialization of untrusted data vulnerabilityIn Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the clas…EPSS 28%7.2CVE-2021-23337Lodash code injection vulnerabilityLodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.EPSS 21%6.5CVE-2021-43797Netty http request smuggling vulnerabilityNetty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients…EPSS 2.7%6.5CVE-2020-5421Vmware spring framework vulnerabilityIn Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against R…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2022-22969), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.