Skip to content
VMwareCVE-2026-47842

VMware Spring Security: weak encryption

Medium6.5CVE-2026-47842 · Published Aug 26, 2026 · updated Sep 4, 2026

Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using a null (all-zero) initialization vector. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25

VMware advisory

Affected versions

PackageAffectedFixed in
Spring Security
Product
<= 7.1.0No fix yet
>= 7.0.0, <= 7.0.6No fix yet
>= 6.5.0, <= 6.5.11No fix yet
>= 6.4.0, <= 6.4.18No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-326

More VMware advisories

All VMware
Advisory
VMware Reactor Netty: open redirect
Medium6.1Aug 26
In specific scenarios involving multiple clients with different DNS resolver...
Low3.7Aug 26
In specific scenarios
Medium5.3Aug 26
Spring Data JPA's Sort validation can be bypassed
Medium4.8Aug 26
VMware Spring Cloud Config: race condition
High7.2Aug 26
VMware Spring Cloud Config: missing authentication
Medium6.8Aug 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.