VMwareCVE-2026-41707
VMware Spring Security: authentication bypass
High7.4CVE-2026-41707 · Published Aug 25, 2026 · updated Sep 24, 2026
Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. This issue affects Spring Security: 7.1.0, from 7.0.0 through 7.0.6, and from 6.5.0 through 6.5.11.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Spring Security Product | <= 7.1.0 | No fix yet |
| >= 7.0.0, <= 7.0.6 | No fix yet | |
| >= 6.5.0, <= 6.5.11 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-294
More VMware advisories
All VMware| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 26 | Spring Data JPA's Sort validation can be bypassed | Medium4.8 | No fix yet |
| Aug 26 | VMware Spring Security: improper authorization | High7.4 | No fix yet |
| Aug 26 | VMware Spring Cloud Config: missing authentication | Medium6.8 | No fix yet |
| Aug 26 | VMware Spring Cloud Config: race condition | High7.2 | No fix yet |
| Aug 25 | Improper handling of case sensitivity | High8.7 | 78.16.0+1 more |
| Aug 24 | VMware Micrometer: denial of service | Medium5.9 | No fix yet |