CVE-2026-22753 — Protection Mechanism Failure in Spring Security
Severity
7.5HIGHNVD
EPSS
0.1%
top 79.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Description
Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be exercised as intended by the application. This can lead to the authentication, authorization, and other security controls being rendered inactive on intended requests.This issue affects Spring Security: from 7.0.0 through 7.0.4.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages6 packages
🔴Vulnerability Details
1📋Vendor Advisories
1Red Hat
▶
💬Community
1Bugzilla▶
CVE-2026-22753 Spring Security: Spring Security: Security bypass due to incorrect servlet path matching↗2026-04-22