VYPR

Maven package

org.springframework.security/spring-security-oauth2-authorization-server

pkg:maven/org.springframework.security/spring-security-oauth2-authorization-server

Vulnerabilities (2)

  • CVE-2026-41008MedJun 10, 2026
    affected >= 7.0.0, < 7.0.6fixed 7.0.6

    Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an

  • CVE-2024-22258MedMar 20, 2024
    affected < 1.1.6fixed 1.1.6

    Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the Authorizat