← Vulnerability feed

Vulnerability record · CVE-2026-22732 · published 19 March 2026

CVE-2026-22732: Vmware spring security vulnerability

Vmware · Spring Security

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

9.1 CVSS 3.1 Critical EPSS 0.48% · top 61.0% CWE-425 · CWE-425
9.1CVSS 3.1 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://spring.io/security/cve-2026-22732 ExploitVendor Advisory

Track CVE-2026-22732 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-34034Vmware spring security vulnerabilityUsing "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlu…EPSS 4.0%9.8CVE-2022-31692Vmware spring security insecure direct object reference vulnerabilitySpring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatc…EPSS 3.6%9.8CVE-2022-22978Vmware spring security incorrect authorization vulnerabilityIn spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be b…EPSS 12%9.8CVE-2014-3527Vmware spring security improper authentication vulnerabilityWhen using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authent…EPSS 1.8%9.1CVE-2026-59270Vmware spring security incorrect authorization vulnerabilitySpring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener t…EPSS 0.40%8.8CVE-2026-59354Vmware spring security improper input validation vulnerabilityIn versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the …EPSS 0.49%8.8CVE-2021-22112Pivotal software spring security vulnerabilitySpring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the…EPSS 3.2%8.1CVE-2026-47838Vmware spring security improper authentication vulnerabilitySubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value fo…EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2026-22732), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.