CVE-2026-22732

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-19 23:16

Updated : 2026-03-20 15:16


NVD link : CVE-2026-22732

Mitre link : CVE-2026-22732

CVE.ORG link : CVE-2026-22732


JSON object : View

Products Affected

No product.

CWE
CWE-425

Direct Request ('Forced Browsing')