CVE-2026-41003: Unencoded HTML Outputs in Spring Security May Allow Cross-Site Scripting
An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters.
Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Spring Securityto a version that resolves this vulnerability.Fixed in 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41003?
CVE-2026-41003 has a severity rating of 7.6, categorized as high.
How do I fix CVE-2026-41003?
To remediate CVE-2026-41003, upgrade to Spring Security version 5.7.24 or later, 5.8.26 or later, 6.3.17 or later, 6.4.17 or later, 6.5.11 or later, or 7.0.0 or later.
What type of vulnerability is CVE-2026-41003?
CVE-2026-41003 is a Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-41003?
CVE-2026-41003 affects users of VMware Spring Security versions 5.7.0 through 5.7.23, 5.8.0 through 5.8.25, and several other versions listed in the description.
What can an attacker do with CVE-2026-41003?
An attacker may exploit CVE-2026-41003 to run arbitrary code on HTML forms generated by Spring Security filters.