VYPR

Maven package

org.springframework.security/spring-security-saml2-service-provider

pkg:maven/org.springframework.security/spring-security-saml2-service-provider

Vulnerabilities (2)

  • CVE-2026-41694LowJun 10, 2026
    affected >= 7.0.0, < 7.0.6fixed 7.0.6

    Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Sprin

  • CVE-2026-40988HigJun 10, 2026
    affected >= 7.0.0, < 7.0.6fixed 7.0.6

    An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory. Affected versions: Spring Security 5.7.