VYPR
High severity7.5NVD Advisory· Published Jun 10, 2026· Updated Jun 12, 2026

CVE-2026-40988

CVE-2026-40988

Description

An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory.

Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.springframework.security:spring-security-saml2-service-providerMaven
>= 7.0.0, < 7.0.67.0.6
org.springframework.security:spring-security-saml2-service-providerMaven
>= 6.5.0, < 6.5.116.5.11
org.springframework.security:spring-security-saml2-service-providerMaven
>= 6.4.0, <= 6.4.16
org.springframework.security:spring-security-saml2-service-providerMaven
>= 6.3.0, <= 6.3.16
org.springframework.security:spring-security-saml2-service-providerMaven
>= 5.8.0, <= 5.8.25
org.springframework.security:spring-security-saml2-service-providerMaven
<= 5.7.23

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

1