Use of Cache Containing Sensitive Information Affecting org.springframework.security:spring-security-web package, versions [3.2.8,6.5.9)[7.0.0-M1,7.0.4)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-15701796
  • published20 Mar 2026
  • disclosed20 Mar 2026
  • creditWyfrel

Introduced: 20 Mar 2026

CVE-2026-22732  (opens in a new tab)
CWE-524  (opens in a new tab)

How to fix?

Upgrade org.springframework.security:spring-security-web to version 6.5.9, 7.0.4 or higher.

Overview

org.springframework.security:spring-security-web is a package within Spring Security that provides security services for the Spring IO Platform.

Affected versions of this package are vulnerable to Use of Cache Containing Sensitive Information in the process of writing HTTP response headers for servlet applications. An attacker can manipulate HTTP responses by exploiting the failure to write expected headers, potentially leading to unauthorized access or information disclosure.

CVSS Base Scores

version 4.0
version 3.1