CVE-2026-22732
published 2026-03-19CVE-2026-22732: When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be…
PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.48%
38.3th percentile
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.
This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers:
: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | spring_security | < 5.7.22 | 5.7.22 |
| vmware | spring_security | 5.7.0 – 5.7.21 | — |
| vmware | spring_security | >= 5.8.0 < 5.8.24 | 5.8.24 |
| vmware | spring_security | 5.8.0 – 5.8.23 | — |
| vmware | spring_security | >= 6.3.0 < 6.3.15 | 6.3.15 |
| vmware | spring_security | 6.3.0 – 6.3.14 | — |
| vmware | spring_security | >= 6.4.0 < 6.4.15 | 6.4.15 |
| vmware | spring_security | 6.4.0 – 6.4.14 | — |
| vmware | spring_security | >= 6.5.0 < 6.5.9 | 6.5.9 |
| vmware | spring_security | 6.5.0 – 6.5.8 | — |
| vmware | spring_security | >= 7.0.0 < 7.0.4 | 7.0.4 |
| vmware | spring_security | 7.0.0 – 7.0.3 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spring Security: Spring Security: Security policy bypass and information disclosure due to unwritten HTTP headers
vendor_redhat·2026-03-19·CVSS 9.1
CVE-2026-22732 [CRITICAL] CWE-166 Spring Security: Spring Security: Security policy bypass and information disclosure due to unwritten HTTP headers
Spring Security: Spring Security: Security policy bypass and information disclosure due to unwritten HTTP headers
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.
This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers:
: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
A flaw was found in Spring Security. When applications using Spring Security specify HTTP response headers for servlet applications, these headers may not be written. This can lead to a bypass of security policies or information disclosure, potentially all
GHSA
Spring Security HTTP Headers Are not Written Under Some Conditions
ghsa·2026-03-20
CVE-2026-22732 [CRITICAL] CWE-425 Spring Security HTTP Headers Are not Written Under Some Conditions
Spring Security HTTP Headers Are not Written Under Some Conditions
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.
This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
OSV
Spring Security HTTP Headers Are not Written Under Some Conditions
osv·2026-03-20
CVE-2026-22732 [CRITICAL] Spring Security HTTP Headers Are not Written Under Some Conditions
Spring Security HTTP Headers Are not Written Under Some Conditions
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.
This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
blogs_hackernews·2026-06-15·CVSS 8.8
CVE-2026-11645 [HIGH] ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod.
This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten software keeps becoming someone else's entry point.
Scroll through the full Monday Cybersecurity Recap below for the news, tools, webinars, and fixes worth your time this week.
## ⚡ Threat of the Week
Google Patches Actively Exploited Chrome 0-Day - G
Hackernews
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
blogs_hackernews·2026-06-10·CVSS 10.0
CVE-2026-25089 [CRITICAL] Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure.
The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It's tracked as CVE-2026-25089 (CVSS score: 9.1).
"An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allo
Bleepingcomputer
SAP fixes critical flaws in NetWeaver and Commerce Cloud
blogs_bleepingcomputer·2026-06-09·CVSS 9.1
CVE-2026-44748 [CRITICAL] SAP fixes critical flaws in NetWeaver and Commerce Cloud
## SAP fixes critical flaws in NetWeaver and Commerce Cloud
## Bill Toulas
SAP has released fixes for 15 vulnerabilities as part of its June 2026 Security Patch package, including four critical-severity flaws affecting SAP NetWeaver and SAP Commerce Cloud.
NetWeaver is SAP's core application platform and middleware stack that provides the foundation for many SAP business applications, including ERP systems, handling functions such as application serving, integration, authentication, user management, and data processing.
Commerce Cloud is an enterprise e-commerce platform (formerly Hybris). It enables organizations to build and manage online stores, digital sales channels, product catalogs, customer accounts, and order management systems for B2B and B2C commerce.
In this month's securi
Bleepingcomputer
The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss
blogs_bleepingcomputer·2026-05-05
CVE-2026-22732 The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss
## The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss
## HeroDevs
Written by Isaac Wuest, Principal Product Manager at HeroDevs.
When security teams think about end-of-life (EOL) open source software, the conversation usually starts and ends in the same place: no more patches.
That's true, but it's only half the story, and arguably the less dangerous half. There are two compounding problems most teams are unaware of.
## Problem One: The CVE Ecosystem Doesn't Investigate What It Doesn't Support
When a vulnerability is discovered in an open source project, maintainers determine which versions are affected and file a CVE with a defined affected range. Every vulnerability scanner, SBOM tool, and CVE feed in the industry consumes that range.
If your version falls outside it, you ge
Wiz
CVE-2026-22732 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2026-22732 [CRITICAL] CVE-2026-22732 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22732 :
Java vulnerability analysis and mitigation
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.
This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers:
: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
Source : NVD
## 9.1
Score
Published March 19, 2026
Severity CRITICAL
CNA Score 9.1
Affected Technologies
Java
Jenkins
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.1
Exploitation Probability (EPSS
Wiz
CVE-2025-22234 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.7
CVE-2025-22234 [LOW] CVE-2025-22234 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-22234 :
Jenkins vulnerability analysis and mitigation
The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.
Source : NVD
## 5.3
Score
Published January 22, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Jenkins
Spring Security
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.springframework.security:spring-security-core
jenkins
Sources
NVD
Maven Severity MEDIUM Has Fix Ad
2026-03-19
Published