cbcvebase.
CVE-2026-47838
published 2026-06-10

CVE-2026-47838: SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the…

PriorityP346high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.12%
1.9th percentile
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected versions: Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10.

Affected

10 ranges
VendorProductVersion rangeFixed in
springspring_security>= 5.7.0 < 5.7.255.7.25
springspring_security>= 5.8.0 < 5.8.275.8.27
springspring_security>= 6.3.0 < 6.3.186.3.18
springspring_security>= 6.4.0 < 6.4.186.4.18
springspring_security>= 6.5.0 < 6.5.10.26.5.10.2
vmwarespring_security< 5.7.255.7.25
vmwarespring_security>= 5.8.0 < 5.8.275.8.27
vmwarespring_security>= 6.3.0 < 6.3.186.3.18
vmwarespring_security>= 6.4.0 < 6.4.186.4.18
vmwarespring_security>= 6.5.0 < 6.5.116.5.11
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.