Denial of Service Vulnerability in Spring Security's SAML 2.0 Login/Logout
CVE-2026-40988
7.5HIGH
What is CVE-2026-40988?
A vulnerability in applications utilizing Spring Security’s SAML 2.0 Login/Logout with REDIRECT binding allows for a denial of service. An unbounded writer can inflate the SAML payload into memory, potentially leading to resource exhaustion. It is crucial for developers and system admins to analyze the affected Spring Security versions to mitigate this risk.
Affected Version(s)
Spring Security 5.7.0 < 5.7.24
Spring Security 5.8.0 < 5.8.26
Spring Security 6.3.0 < 6.3.17
