CVE-2026-47838
published 2026-06-10CVE-2026-47838: SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the…
PriorityP346high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.12%
1.9th percentile
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.
Affected versions:
Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_security | >= 5.7.0 < 5.7.25 | 5.7.25 |
| spring | spring_security | >= 5.8.0 < 5.8.27 | 5.8.27 |
| spring | spring_security | >= 6.3.0 < 6.3.18 | 6.3.18 |
| spring | spring_security | >= 6.4.0 < 6.4.18 | 6.4.18 |
| spring | spring_security | >= 6.5.0 < 6.5.10.2 | 6.5.10.2 |
| vmware | spring_security | < 5.7.25 | 5.7.25 |
| vmware | spring_security | >= 5.8.0 < 5.8.27 | 5.8.27 |
| vmware | spring_security | >= 6.3.0 < 6.3.18 | 6.3.18 |
| vmware | spring_security | >= 6.4.0 < 6.4.18 | 6.4.18 |
| vmware | spring_security | >= 6.5.0 < 6.5.11 | 6.5.11 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username.
ghsa_unreviewed·2026-06-10
CVE-2026-47838 [MEDIUM] CWE-287 SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username.
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.
Affected versions:
Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.
GHSA
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
ghsa·2026-06-10
CVE-2026-47838 [MEDIUM] CWE-287 Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
In Spring Security Web, `SubjectDnX509PrincipalExtractor` does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user.
`SubjectDnX509PrincipalExtractor` is deprecated by this CVE and replaced with `SubjectX500PrincipalExtractor`. As part of updating, you should also migrate to `SubjectX500PrincipalExtractor`.
Affected versions:
Spring Security Enterprise 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.
OSS 6.5.0 through 6.5.10.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-10
Published