Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-22732

Опубликовано: 19 мар. 2026
Источник: debian
EPSS Низкий

Описание

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libspring-security-2.0-javanot-affectedpackage

Примечания

  • https://spring.io/security/cve-2026-22732

EPSS

Процентиль: 2%
0.00014
Низкий

Связанные уязвимости

CVSS3: 6.5
redhat
12 дней назад

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

CVSS3: 9.1
nvd
12 дней назад

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

CVSS3: 9.1
github
12 дней назад

Spring Security HTTP Headers Are not Written Under Some Conditions

CVSS3: 9.1
fstec
13 дней назад

Уязвимость Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, связанная с использованием небезопасной прямой ссылкой на объект, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 2%
0.00014
Низкий