Spring Product Security Update Advisory (CVE-2026-47838)
Overview
A security update has been released to address vulnerabilities in Spring products. Users of these products should update to the latest version.
Affected Products and Scope of Impact
- Spring Security versions 5.7.0 through 5.7.24.
- Spring Security versions 5.8.0 through 5.8.26.
- Spring Security versions 6.3.0 through 6.3.17.
- Spring Security versions 6.4.0 through 6.4.17.
- Spring Security versions 6.5.0 through 6.5.10.
Resolved Vulnerabilities
- CVE-2026-47838 is an unauthorized user impersonation vulnerability in Spring Security.
- This issue can be resolved by updating to the latest version with the Vulnerability Patch as instructed on the reference site.
Versions with Vulnerability Patches
- Spring Security 5.7.25.
- Spring Security 5.8.27.
- Spring Security 6.3.18.
- Spring Security 6.4.18.
- Spring Security 6.5.11.
Reference
- CVE-2026-47838: Unauthorized User Impersonation when Using X.509 Client Certificates.