VYPR

Spring Authorization Server

by Spring Projects

Source repositories

CVEs (2)

  • CVE-2026-41008MedJun 10, 2026
    risk 0.40cvss 6.1epss 0.00

    Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an…

  • CVE-2024-22258MedMar 20, 2024
    risk 0.33cvss 6.1epss 0.00

    Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confidential Client uses PKCE for the…