CVE-2026-22732

Source
https://cve.org/CVERecord?id=CVE-2026-22732
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-22732.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-22732
Aliases
Downstream
Related
Published
2026-03-19T22:47:38.199Z
Modified
2026-05-18T05:58:31.698976339Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Under Some Conditions Spring Security HTTP Headers Are not Written
Details

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers:

: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

Database specific
{
    "cna_assigner": "vmware",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "5.7.0"
                },
                {
                    "last_affected": "5.7.21"
                },
                {
                    "introduced": "5.8.0"
                },
                {
                    "last_affected": "5.8.23"
                },
                {
                    "introduced": "6.3.0"
                },
                {
                    "last_affected": "6.3.14"
                },
                {
                    "introduced": "6.4.0"
                },
                {
                    "last_affected": "6.4.14"
                },
                {
                    "introduced": "6.5.0"
                },
                {
                    "last_affected": "6.5.8"
                },
                {
                    "introduced": "7.0.0"
                },
                {
                    "last_affected": "7.0.3"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "introduced": "5.7.0"
                },
                {
                    "fixed": "5.7.21"
                },
                {
                    "introduced": "5.8.0"
                },
                {
                    "fixed": "5.8.23"
                },
                {
                    "introduced": "6.3.0"
                },
                {
                    "fixed": "6.3.14"
                },
                {
                    "introduced": "6.4.0"
                },
                {
                    "fixed": "6.4.14"
                },
                {
                    "introduced": "6.5.0"
                },
                {
                    "fixed": "6.5.8"
                },
                {
                    "introduced": "7.0.0"
                },
                {
                    "fixed": "7.0.3"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22732.json"
}
References

Affected packages

Git / github.com/spring-projects/spring-security

Affected ranges

Type
GIT
Repo
https://github.com/spring-projects/spring-security
Events
Database specific
{
    "source": "CPE_FIELD",
    "cpe": "cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "6.5.0"
        },
        {
            "fixed": "6.5.9"
        },
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.0.4"
        }
    ]
}

Affected versions

6.*
6.5.0
6.5.1
6.5.3
6.5.4
6.5.5
6.5.6
6.5.7
6.5.8
7.*
7.0.0
7.0.1
7.0.2
7.0.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-22732.json"