VYPR

Spring Authorization Server

by Spring Security

CVEs (2)

  • CVE-2026-22752CriJul 16, 2026
    risk 0.62cvss 9.6epss 0.00

    Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.

  • CVE-2026-47877HigAug 27, 2026
    risk 0.53cvss 8.2epss 0.00

    Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6