CVE-2026-40988: Unbounded DEFLATE Inflation in SAML 2.0 Service Provider
An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory.
Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40988?
The severity of CVE-2026-40988 is rated as high with a score of 7.5.
How do I fix CVE-2026-40988?
To fix CVE-2026-40988, upgrade to Spring Security versions beyond 5.7.23 or 5.8.
What systems are affected by CVE-2026-40988?
CVE-2026-40988 affects applications using spring-security-saml2-service-provider with the REDIRECT binding for SAML 2.0.
What type of attack does CVE-2026-40988 expose my application to?
CVE-2026-40988 exposes your application to a denial of service attack through unbounded memory inflation.
Which versions of Spring Security are vulnerable to CVE-2026-40988?
Spring Security versions 5.7.0 to 5.7.23 and 5.8 are vulnerable to CVE-2026-40988.