Input validation error in Spring Security - CVE-2026-22752

 

Input validation error in Spring Security - CVE-2026-22752

Published: April 27, 2026


Vulnerability identifier: #VU128223
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-22752
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to conduct cross-site scripting, escalate privileges, or trigger server-side request forgery.

The vulnerability exists due to improper input validation in dynamic client registration endpoints when processing crafted client metadata fields. A remote user can register a malicious client with crafted metadata to conduct cross-site scripting, escalate privileges, or trigger server-side request forgery.

Only deployments with dynamic client registration explicitly enabled are vulnerable.


Affected software

Spring Security
Spring Authorization Server
Library Support for Spring
IBM Sterling File Gateway
IBM Sterling B2B Integrator

How to mitigate CVE-2026-22752

Install security update from vendor's website.

Spring Security - update to 7.0.5
Spring Authorization Server - addressed in versions 1.3.11, 1.4.10, 1.5.7
Library Support for Spring - update to 3.4.18
IBM Sterling File Gateway - update to 6.2.2.1
IBM Sterling B2B Integrator - update to 6.2.2.1

External References

Related Security Bulletins