Dependency scanning
Check whether org.springframework.security:spring-security-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-22751
Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
CVE-2026-22746
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
CVE-2025-41248
Spring Security annotation detection mechanism has authorization bypass
CVE-2024-38827
Spring Framework has Authorization Bypass for Case Sensitive Comparisons
CVE-2024-22257
Erroneous authentication pass in Spring Security
CVE-2025-22223
Spring Security Vulnerable to Authorization Bypass via Security Annotations
CVE-2025-22234
Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvide
CVE-2025-41232
Spring Security authorization bypass for method security annotations on private methods
CVE-2024-38810
Spring Security Missing Authorization vulnerability
CVE-2024-22234
Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated
CVE-2011-2731
Concurrent Execution using Shared Resource with Improper Synchronization in Spring Security
CVE-2012-5055
Exposure of Sensitive Information to an Unauthorized Actor in Spring Security
CVE-2011-2732
Improper Control of Generation of Code in Spring Security
CVE-2010-3700
Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security
CVE-2011-2894
Spring Framework and Spring Security vulnerable to Deserialization of Untrusted Data
CVE-2016-5007
Spring Security and Spring Framework may not recognize certain paths that should be protected
CVE-2016-9879
Security Constraint Bypass in Spring Security
CVE-2022-22978
Authorization bypass in Spring Security
CVE-2022-22976
Integer overflow in BCrypt class in Spring Security
CVE-2014-3527
Authorization Bypass in Spring Security
CVE-2018-1199
Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core
CVE-2018-15801
Spring Security vulnerable to Authorization Bypass
CVE-2017-4995
Deserialization of Untrusted Data in Spring Security
CVE-2022-31692
Spring Security authorization rules can be bypassed via forward or include dispatcher types
CVE-2023-20862
Spring Security logout not clearing security context
CVE-2021-22119
Resource Exhaustion in Spring Security
CVE-2020-5408
Insufficient Entropy in Spring Security
CVE-2020-5407
Signature wrapping vulnerability in Spring Security
CVE-2019-3795
Spring Security uses insufficiently random values
CVE-2019-11272
Insufficiently Protected Credentials and Improper Authentication in Spring Security
CVE-2014-0097
Improper Authentication in Spring Security
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes