Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. This issue affects Spring Security: 7.1.0, from 7.0.0 through 7.0.6, and from 6.5.0 through 6.5.11.
References
History

Wed, 26 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-309
CWE-615

Wed, 26 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-309
CWE-615

Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Description Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. This issue affects Spring Security: 7.1.0, from 7.0.0 through 7.0.6, and from 6.5.0 through 6.5.11.
First Time appeared Spring
Spring spring Security
Weaknesses CWE-294
CPEs cpe:2.3:a:spring:spring_security:*:*:*:*:*:*:*:*
cpe:2.3:a:spring:spring_security:7.1.0:*:*:*:*:*:*:*
Vendors & Products Spring
Spring spring Security

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Description Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11
Title Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-08-25T23:50:14.613Z

Reserved: 2026-04-22T06:21:34.490Z

Link: CVE-2026-41707

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T23:16:59.933

Modified: 2026-08-25T23:16:59.933

Link: CVE-2026-41707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T03:30:04Z