CVE-2026-22732
Under Some Conditions Spring Security HTTP Headers Are not Written
CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
2th
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
| Vendor | vmware |
| Product | spring security |
| Ecosystems | |
| Industries | TechnologyEnterprise |
| Published | Mar 19, 2026 |
| Last Updated | Apr 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for vmware spring security
Be the first to know when new critical vulnerabilities affecting vmware spring security are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
VMware / Spring Security
5.7.0 ≤ 5.7.21 5.8.0 ≤ 5.8.23 6.3.0 ≤ 6.3.14 6.4.0 ≤ 6.4.14 6.5.0 ≤ 6.5.8 7.0.0 ≤ 7.0.3