VYPR

Spring Security

by Spring Projects

Source repositories

CVEs (2)

  • CVE-2026-59354CriAug 27, 2026
    risk 0.62cvss 9.6epss

    In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An…

  • CVE-2026-59270CriAug 27, 2026
    risk 0.61cvss 9.4epss

    Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring…