Implementation Flaw in Spring Security's JWT Decoding Features
CVE-2026-22748

5.3MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
22 April 2026

What is CVE-2026-22748?

A vulnerability exists in Spring Security related to the configuration of JSON Web Token (JWT) decoding using NimbusJwtDecoder or NimbusReactiveJwtDecoder. Applications not configuring an OAuth2TokenValidator properly may expose themselves to potential security risks. This flaw affects multiple versions of Spring Security, highlighting the importance of secure JWT processing in application security.

Affected Version(s)

Spring Security 6.3.0 <= 6.3.14

Spring Security 6.4.0 <= 6.4.14

Spring Security 6.5.0 <= 6.5.9

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.