CVE-2026-59276: Timing Attack via Non-Constant-Time Comparison of Sensitive Values

Published Aug 27, 2026
·
Updated

Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject an incorrect value is proportional to the number of leading characters that match the expected value. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25

Affected Software

6 affected components
Spring Spring Security>=7.0.0<=7.0.6
Spring Spring Security>=6.5.0<=6.5.11
Spring Spring Security>=6.4.0<=6.4.18
Spring Spring Security>=5.8.0<=5.8.27
Spring Spring Security>=5.7.0<=5.7.25
Spring Spring Security=7.1.0

Event History

Aug 27, 2026
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverity

Frequently Asked Questions

1

Which Spring Security versions are affected?

Affected versions are Spring Security 7.1.0; 7.0.0 through 7.0.6; 6.5.0 through 6.5.11; 6.4.0 through 6.4.18; 5.8.0 through 5.8.27; and 5.7.0 through 5.7.25.

2

What does an attacker need to exploit this issue?

The issue is remotely reachable without privileges or user interaction, but exploitation has high attack complexity. An attacker would need to make comparisons against a sensitive value and reliably measure timing differences that reveal how many leading characters matched.

3

What is the potential impact if exploitation succeeds?

Successful exploitation may disclose sensitive values through timing differences. The provided assessment indicates high confidentiality impact, with no integrity or availability impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203