CVE-2026-59276
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject an incorrect value is proportional to the number of leading characters that match the expected value. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Security | 7.1.0 | affected |
| Spring | Spring Security | 7.0.0 <= 7.0.6 | affected |
| Spring | Spring Security | 6.5.0 <= 6.5.11 | affected |
| Spring | Spring Security | 6.4.0 <= 6.4.18 | affected |
| Spring | Spring Security | 5.8.0 <= 5.8.27 | affected |
| Spring | Spring Security | 5.7.0 <= 5.7.25 | affected |
Weaknesses
- CWE-208 Observable Timing Discrepancy
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.