Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4vrc-j85c-598c | Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules |
Tue, 28 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Tue, 28 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-551 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 24 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware spring Security |
|
| CPEs | cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vmware
Vmware spring Security |
Wed, 22 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Security |
|
| Vendors & Products |
Spring
Spring spring Security |
Wed, 22 Apr 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Wed, 22 Apr 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4. | |
| Title | ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-04-22T15:59:52.492Z
Reserved: 2026-01-09T06:55:03.991Z
Link: CVE-2026-22754
Updated: 2026-04-22T15:44:19.919Z
Status : Analyzed
Published: 2026-04-22T06:16:04.270
Modified: 2026-04-24T14:16:07.313
Link: CVE-2026-22754
OpenCVE Enrichment
Updated: 2026-04-29T00:30:16Z
Github GHSA