Intel

AIKIDO-2026-10580

spring-security-oauth2-authorization-server is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2026-22752 Published Apr 27, 2026

95

Critical Risk

This Affects:

JAVAspring-security-oauth2-authorization-server
1.3.0 - 1.3.10
Fixed in 1.3.11
1.4.0 - 1.4.9
Fixed in 1.4.10
1.5.0 - 1.5.6
Fixed in 1.5.7
7.0.0 - 7.0.4
Fixed in 7.0.5
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper input validation in Dynamic Client Registration endpoints because certain client metadata fields are insufficiently validated when the feature is enabled. An attacker with a valid Initial Access Token may register a malicious client with crafted metadata, potentially leading to stored cross-site scripting, privilege escalation, or server-side request forgery.

Who does this affect?

You are affected if using a vulnerable version.

Background info

spring-security-oauth2-authorization-server is vulnerable to Improper Input Validation in versions 1.3.0 - 1.3.10, 1.4.0 - 1.4.9, 1.5.0 - 1.5.6 and 7.0.0 - 7.0.4.

How to fix this

Upgrade the org.springframework.security:spring-security-oauth2-authorization-server library to the patch version.