Launch Week Day 1: Announcing Security Design Review
maven

org.springframework.security:spring-security-core

View on maven registry
31 Total advisories
31 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 4.8
Maven

CVE-2026-22751

Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured

LOW 3.7
Maven

CVE-2026-22746

Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider

HIGH 7.5
Maven

CVE-2025-41248

Spring Security annotation detection mechanism has authorization bypass

MEDIUM 5.3
Maven

CVE-2025-22223

Spring Security Vulnerable to Authorization Bypass via Security Annotations

MEDIUM 4.8
Maven

CVE-2024-38827

Spring Framework has Authorization Bypass for Case Sensitive Comparisons

HIGH 8.2
Maven

CVE-2024-22257

Erroneous authentication pass in Spring Security

MEDIUM 5.3
Maven

CVE-2025-22234

Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvide

CRITICAL 9.1
Maven

CVE-2025-41232

Spring Security authorization bypass for method security annotations on private methods

MEDIUM 6.5
Maven

CVE-2024-38810

Spring Security Missing Authorization vulnerability

HIGH 7.4
Maven

CVE-2024-22234

Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated

UNKNOWN
Maven

CVE-2011-2731

Concurrent Execution using Shared Resource with Improper Synchronization in Spring Security

UNKNOWN
Maven

CVE-2012-5055

Exposure of Sensitive Information to an Unauthorized Actor in Spring Security

UNKNOWN
Maven

CVE-2011-2732

Improper Control of Generation of Code in Spring Security

UNKNOWN
Maven

CVE-2010-3700

Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security

UNKNOWN
Maven

CVE-2011-2894

Spring Framework and Spring Security vulnerable to Deserialization of Untrusted Data

HIGH 7.5
Maven

CVE-2016-5007

Spring Security and Spring Framework may not recognize certain paths that should be protected

HIGH 7.5
Maven

CVE-2016-9879

Security Constraint Bypass in Spring Security

CRITICAL 9.8
Maven

CVE-2022-22978

Authorization bypass in Spring Security

MEDIUM 5.3
Maven

CVE-2022-22976

Integer overflow in BCrypt class in Spring Security

CRITICAL 9.8
Maven

CVE-2014-3527

Authorization Bypass in Spring Security

MEDIUM 5.3
Maven

CVE-2018-1199

Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core

HIGH 7.4
Maven

CVE-2018-15801

Spring Security vulnerable to Authorization Bypass

HIGH 8.1
Maven

CVE-2017-4995

Deserialization of Untrusted Data in Spring Security

CRITICAL 9.8
Maven

CVE-2022-31692

Spring Security authorization rules can be bypassed via forward or include dispatcher types

MEDIUM 6.3
Maven

CVE-2023-20862

Spring Security logout not clearing security context

HIGH 7.5
Maven

CVE-2021-22119

Resource Exhaustion in Spring Security

MEDIUM 6.5
Maven

CVE-2020-5408

Insufficient Entropy in Spring Security

HIGH 8.8
Maven

CVE-2020-5407

Signature wrapping vulnerability in Spring Security

MEDIUM 5.3
Maven

CVE-2019-3795

Spring Security uses insufficiently random values

HIGH 7.3
Maven

CVE-2019-11272

Insufficiently Protected Credentials and Improper Authentication in Spring Security

HIGH 7.3
Maven

CVE-2014-0097

Improper Authentication in Spring Security

Ready to move

Start Securing

Free, no credit card | First findings in minutes