Medium severity6.8NVD Advisory· Published Jun 10, 2026· Updated Jun 10, 2026
CVE-2026-47838
CVE-2026-47838
Description
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.
Affected versions: Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- Range: >=5.7.0,<5.7.25,>=5.8.0,<5.8.27,>=6.3.0,<6.3.18,>=6.4.0,<6.4.18,>=6.5.0,<6.5.11
- Range: 5.7.0 through 5.7.24, 5.8.0 through 5.8.26, 6.3.0 through 6.3.17, 6.4.0 through 6.4.17, 6.5.0 through 6.5.10
- osv-coords7 versionspkg:apk/chainguard/jenkins-2.555pkg:apk/chainguard/jenkins-2.555-openjdk-21pkg:apk/chainguard/jenkins-2.555-openjdk-25pkg:apk/chainguard/kafbat-uipkg:apk/chainguard/kafbat-ui-fipspkg:apk/chainguard/nacospkg:apk/chainguard/nacos-docker
< 2.555.3-r1+ 6 more
- (no CPE)range: < 2.555.3-r1
- (no CPE)range: < 2.555.3-r1
- (no CPE)range: < 2.555.3-r1
- (no CPE)range: < 1.5.0-r5
- (no CPE)range: < 1.5.0-r4
- (no CPE)range: < 3.2.3-r1
- (no CPE)range: < 3.2.3-r1
Patches
Vulnerability mechanics
References
1News mentions
1- Spring Projects: 25 Vulnerabilities Disclosed, Including SpEL Injection and Deserialization FlawsVypr Intelligence · Jun 10, 2026