Protection Mechanism Failure in Spring Security - CVE-2026-22732

 

Protection Mechanism Failure in Spring Security - CVE-2026-22732

Published: April 28, 2026


Vulnerability identifier: #VU128373
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-22732
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper security header handling in HTTP response header writing for servlet applications when using lazy writing of HTTP headers. A remote attacker can trigger application responses where the configured security headers are not written to disclose sensitive information.

This issue affects servlet applications that specify HTTP response headers using Spring Security with lazy header writing enabled.


Affected software

Spring Security
Library Support for Spring
Crowd Data Center
IBM Sterling B2B Integrator
IBM Sterling Control Center
Jira Software Data Center
Jira Service Management Data Center
IBM Sterling File Gateway
IBM Sterling Connect:Direct for Microsoft Windows

How to mitigate CVE-2026-22732

Install security update from vendor's website.

Spring Security - addressed in versions 5.7.22, 5.8.24, 6.3.15, 6.4.15, 6.5.9, 7.0.4
Crowd Data Center - update to 7.2.0
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.1
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.1
IBM Sterling Control Center - addressed in versions 6.3.1.0.8, 6.4.1.0.2, 6.4.2.0.3
Jira Software Data Center - addressed in versions 10.3.7, 11.3.5
Jira Service Management Data Center - addressed in versions 10.3.7, 11.3.5
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.45, 6.4.0.4.17

External References

Related Security Bulletins