CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Broadcom 1Spring Authorization Server Aug 31, 2026 Aug 27, 2026 N/A· v4 8.2 HIGH· v3 N/A· v2 Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malici...Show more |
1Broadcom 1Spring Authorization Server Sep 1, 2026 Aug 27, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri...Show more |
1Broadcom 1Spring Authorization Server Sep 4, 2026 Jul 16, 2026 N/A· v4 9.6 CRITICAL· v3 N/A· v2 Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 thro...Show more |
2Broadcom Vmware2Spring Authorization Server Spring SecurityJul 17, 2026 Jun 10, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and a...Show more |