Known vulnerabilities in Spring Authorization Server
Vendor:
Spring
Software:
Spring Authorization Server
Software CPE:
cpe:2.3:a:spring:spring_authorization_server:*:*:*:*:*:*:*:*
Website:
https://spring.io/
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
1.5.8
1.4.10
1.3.11
1.3.10
1.3.9
1.3.8
1.4.9
1.5.7
1.5.6
1.5.5
1.4.8
1.5.4
1.4.7
1.5.3
1.4.6
1.5.2
1.4.5
1.5.1
1.4.4
1.3.7
1.5.0
1.4.3
1.3.6
1.4.2
1.3.5
1.4.1
1.3.4
1.4.0
1.3.3
1.2.7
1.3.2
1.2.6
1.3.1
1.2.5
1.3.0
1.2.4
1.1.7
1.0.6
1.2.3
1.2.2
1.2.1
1.2.0
1.1.6
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
0.4.5
0.4.4
0.4.3
0.4.2
0.4.1
0.4.0
0.3.1
0.3.0
0.2.3
0.2.2
0.2.1
0.2.0
0.1.2
0.1.1
0.1.0
0.0.3
0.0.2
0.0.1
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU128223 - Improper input validation CVE-2026-22752 |
CWE-20 | Medium | 1.3.11, 1.4.10, 1.5.7 | 27.04.2026 |
SB20260427181 SB20260427183 SB2026052513 and 1 more |
||
| #VU87654 - Improper Authentication CVE-2024-22258 |
CWE-287 | Medium | 1.0.6, 1.1.6, 1.2.3 | 20.03.2024 |
SB2024032029 SB2024090359 |