CVE-2026-22732
critical · 9.1When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
9.1
CVSS
0.5%
EPSS (exploit prob.)
41st
EPSS percentile
2026-03-19
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-425
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| vmware | spring_security | < 5.7.22 |
| vmware | spring_security | >= 5.8.0, < 5.8.24 |
| vmware | spring_security | >= 6.3.0, < 6.3.15 |
| vmware | spring_security | >= 6.4.0, < 6.4.15 |
| vmware | spring_security | >= 6.5.0, < 6.5.9 |
| vmware | spring_security | >= 7.0.0, < 7.0.4 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-22732