Medium severity6.8NVD Advisory· Published Jun 10, 2026· Updated Jun 10, 2026
CVE-2026-47838
CVE-2026-47838
Description
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.
Affected versions: Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework.security:spring-security-webMaven | >= 6.5.0, < 6.5.11 | 6.5.11 |
org.springframework.security:spring-security-webMaven | >= 6.4.0, <= 6.4.13 | — |
org.springframework.security:spring-security-webMaven | >= 6.0.0, <= 6.3.10 | — |
org.springframework.security:spring-security-webMaven | >= 5.8.0, <= 5.8.16 | — |
org.springframework.security:spring-security-webMaven | <= 5.7.14 | — |
Affected products
9- Range: >=5.7.0,<5.7.25,>=5.8.0,<5.8.27,>=6.3.0,<6.3.18,>=6.4.0,<6.4.18,>=6.5.0,<6.5.11
- Range: 5.7.0 through 5.7.24, 5.8.0 through 5.8.26, 6.3.0 through 6.3.17, 6.4.0 through 6.4.17, 6.5.0 through 6.5.10
- osv-coords7 versionspkg:apk/chainguard/jenkins-2.555pkg:apk/chainguard/jenkins-2.555-openjdk-21pkg:apk/chainguard/jenkins-2.555-openjdk-25pkg:apk/chainguard/kafbat-uipkg:apk/chainguard/kafbat-ui-fipspkg:apk/chainguard/nacospkg:apk/chainguard/nacos-docker
< 2.555.3-r1+ 6 more
- (no CPE)range: < 2.555.3-r1
- (no CPE)range: < 2.555.3-r1
- (no CPE)range: < 2.555.3-r1
- (no CPE)range: < 1.5.0-r5
- (no CPE)range: < 1.5.0-r4
- (no CPE)range: < 3.2.3-r1
- (no CPE)range: < 3.2.3-r1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-293q-567p-wmwqghsaADVISORY
- github.com/advisories/GHSA-2jrg-rf5x-568gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-47838ghsaADVISORY
- spring.io/security/cve-2026-47838nvdWEB
- spring-projects/spring-securityghsaPACKAGE
News mentions
1- Spring Projects: 25 Vulnerabilities Disclosed, Including SpEL Injection and Deserialization FlawsVypr Intelligence · Jun 10, 2026