Resource exhaustion in Spring Security - CVE-2026-40988
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled memory allocation in SAML 2.0 service provider redirect binding processing when inflating a compressed SAML payload into memory. A remote attacker can send a specially crafted compressed SAML payload to cause a denial of service.
The issue affects applications using the REDIRECT binding for SAML 2.0 Login or Logout.