Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-22753

Опубликовано: 22 апр. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be exercised as intended by the application. This can lead to the authentication, authorization, and other security controls being rendered inactive on intended requests.This issue affects Spring Security: from 7.0.0 through 7.0.4.

A flaw was found in Spring Security. When an application uses specific configurations involving securityMatchers(String) and PathPatternRequestMatcher.Builder to handle servlet paths, the intended security controls may not be applied. This can result in a security bypass, where authentication and authorization mechanisms are rendered inactive, potentially allowing an attacker to gain unauthorized access or perform actions without proper validation.

Меры по смягчению последствий

Applications using Spring Security should review their configurations to ensure that securityMatchers(String) and PathPatternRequestMatcher.Builder are correctly implemented to prevent unintended security bypasses. Avoid configurations that prepend a servlet path using PathPatternRequestMatcher.Builder in conjunction with securityMatchers(String) if not explicitly required and thoroughly validated. Consult Spring Security documentation for best practices regarding servlet path matching and security filter chain configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsFix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Fix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Fix deferred
Red Hat build of Apache Camel for Spring Boot 4spring-security-coreFix deferred
Red Hat build of Apache Camel - HawtIO 4spring-security-coreFix deferred
Red Hat build of Quarkusquarkus-spring-security-core-apiFix deferred
Red Hat Data Grid 8spring-security-coreFix deferred
Red Hat Fuse 7org.apache.servicemix.bundles.spring-security-coreFix deferred
Red Hat Fuse 7spring-security-coreFix deferred
Red Hat JBoss Enterprise Application Platform 7spring-security-coreFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-551
https://bugzilla.redhat.com/show_bug.cgi?id=2460486Spring Security: Spring Security: Security bypass due to incorrect servlet path matching

EPSS

Процентиль: 16%
0.00248
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be exercised as intended by the application. This can lead to the authentication, authorization, and other security controls being rendered inactive on intended requests.This issue affects Spring Security: from 7.0.0 through 7.0.4.

CVSS3: 7.5
nvd
4 месяца назад

Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be exercised as intended by the application. This can lead to the authentication, authorization, and other security controls being rendered inactive on intended requests.This issue affects Spring Security: from 7.0.0 through 7.0.4.

CVSS3: 7.5
debian
4 месяца назад

Vulnerability in Spring Spring Security. If an application is usingsec ...

CVSS3: 7.5
github
4 месяца назад

Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers

EPSS

Процентиль: 16%
0.00248
Низкий

6.5 Medium

CVSS3