CVE-2026-41003: VMware Spring Security

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

Affected products

  • VMware Spring Security: from 5.7.0, before 5.7.24 (fixed in 5.7.24); from 5.8.0, before 5.8.26 (fixed in 5.8.26); from 6.3.0, before 6.3.17 (fixed in 6.3.17); from 6.4.0, before 6.4.17 (fixed in 6.4.17); from 6.5.0, before 6.5.10.2 (fixed in 6.5.10.2); from 7.0.0, before 7.0.5.1 (fixed in 7.0.5.1)

Published 2026-06-10. Last modified 2026-07-23.