CVE-2026-41003
MEDIUM WAF: High
CVSS 5.4
Published: 2026-06-10
CWE-79
An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
WAF Coverage Analysis
Cross-Site Scripting (XSS)
High WAF Coverage
OWASP: A03:2021 Injection
941xxx - XSS / XXE
Affected Software
| Vendor | Product | Version |
|---|---|---|
| vmware | spring_security | 5.7.0 - 5.7.24 |
| vmware | spring_security | 5.8.0 - 5.8.26 |
| vmware | spring_security | 6.3.0 - 6.3.17 |
| vmware | spring_security | 6.4.0 - 6.4.17 |
| vmware | spring_security | 6.5.0 - 6.5.11 |
| vmware | spring_security | 7.0.0 - 7.0.6 |
References
- spring.io (Vendor Advisory)