Cross-site scripting in Spring Security - CVE-2026-41003
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code in the victim's browser.
The vulnerability exists due to cross-site scripting in HTML forms generated by Spring Security filters when processing influenced values in RelyingPartyRegistration. A remote user can supply crafted values to execute arbitrary code in the victim's browser.
User interaction is required to load the generated HTML form.