CVE-2026-22732Forced Browsing in Vmware Spring Security

Severity
9.1CRITICALNVD
EPSS
0.0%
top 95.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 19
Latest updateMar 20

Description

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages1 packages

CVEListV5vmware/spring_security5.7.05.7.21+5

🔴Vulnerability Details

3
GHSA
Spring Security HTTP Headers Are not Written Under Some Conditions2026-03-20
OSV
Spring Security HTTP Headers Are not Written Under Some Conditions2026-03-20
CVEList
Under Some Conditions Spring Security HTTP Headers Are not Written2026-03-19

📋Vendor Advisories

1
Red Hat
Spring Security: Spring Security: Security policy bypass and information disclosure due to unwritten HTTP headers2026-03-19

🕵️Threat Intelligence

1
Wiz
CVE-2026-22732 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-22732 — Forced Browsing in Vmware | cvebase