Access Control Bypass Affecting org.springframework.security:spring-security-core package, versions [7.1.0,7.1.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.21% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-19267439
  • published26 Aug 2026
  • disclosed20 Aug 2026
  • creditUnknown

Introduced: 20 Aug 2026

NewCVE-2026-59277  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

Upgrade org.springframework.security:spring-security-core to version 7.1.1 or higher.

Overview

org.springframework.security:spring-security-core is a package that provides security services for the Spring IO Platform.

Affected versions of this package are vulnerable to Access Control Bypass in the InetAddressMatchers process. An attacker can bypass network-based access control checks by supplying the IPv4 or IPv6 "any local" addresses (0.0.0.0 or ::), which are incorrectly classified as external rather than internal. This is only exploitable if the application uses InetAddressMatchers.matchInternal() or InetAddressMatchers.matchExternal() and relies on their classification to make access control decisions for 0.0.0.0 or ::.

CVSS Base Scores

version 4.0
version 3.1