← All CVEs

CVE-2026-22732

critical · 9.1

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

9.1
CVSS
0.5%
EPSS (exploit prob.)
41st
EPSS percentile
2026-03-19
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-425

Affected products

VendorProductAffected versions
vmwarespring_security< 5.7.22
vmwarespring_security>= 5.8.0, < 5.8.24
vmwarespring_security>= 6.3.0, < 6.3.15
vmwarespring_security>= 6.4.0, < 6.4.15
vmwarespring_security>= 6.5.0, < 6.5.9
vmwarespring_security>= 7.0.0, < 7.0.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-22732