Replay Attack Affecting org.springframework.security:spring-security-oauth2-jose package, versions [6.5.0, 7.0.7)[7.1.0, 7.1.1)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.25% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-19268249
  • published26 Aug 2026
  • disclosed20 Aug 2026
  • creditYu Bao from PayPal Cybersecurity Team

Introduced: 20 Aug 2026

NewCVE-2026-41707  (opens in a new tab)
CWE-294  (opens in a new tab)

How to fix?

Upgrade org.springframework.security:spring-security-oauth2-jose to version 7.0.7, 7.1.1 or higher.

Overview

org.springframework.security:spring-security-oauth2-jose is a provides security services for the Spring IO Platform.

Affected versions of this package are vulnerable to Replay Attack through the DPoPProofJwtDecoderFactory. An attacker can gain unauthorized access and impersonate a victim by flooding the server with dummy requests to evict legitimate JWT ID claims from the internal cache, allowing replay of intercepted DPoP proofs.

CVSS Base Scores

version 4.0
version 3.1