4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.springframework.security:spring-security-saml2-service-provider is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.6
CVE-2026-41003
Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters
HIGH 7.3
CVE-2026-40993
Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository
LOW 3.7
CVE-2026-41694
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
HIGH 7.5
CVE-2026-40988
Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes