Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

redhat логотип

CVE-2026-22732

5 месяцев назад

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-22732

5 месяцев назад

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-22732

5 месяцев назад

When applications specify HTTP response headers for servlet applicatio ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-mf92-479x-3373

5 месяцев назад

Spring Security HTTP Headers Are not Written Under Some Conditions

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2026-03480

5 месяцев назад

Уязвимость Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, связанная с использованием небезопасной прямой ссылкой на объект, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-22732

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-22732

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

CVSS3: 9.1
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-22732

When applications specify HTTP response headers for servlet applicatio ...

CVSS3: 9.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-mf92-479x-3373

Spring Security HTTP Headers Are not Written Under Some Conditions

CVSS3: 9.1
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-03480

Уязвимость Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, связанная с использованием небезопасной прямой ссылкой на объект, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.1
0%
Низкий
5 месяцев назад

Уязвимостей на страницу