Intel

AIKIDO-2026-160367

spring-security-saml2-service-provider is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CVE-2026-41003 Published Jun 12, 2026

75

High Risk

This Affects:

JAVAspring-security-saml2-service-provider
0.0.1 - 5.7.23
Fixed in 5.7.24
5.8.0 - 5.8.25
Fixed in 5.8.26
6.0.0 - 6.3.16
Fixed in 6.3.17
6.4.0 - 6.4.16
Fixed in 6.4.17
6.5.0 - 6.5.10
Fixed in 6.5.11
7.0.0 - 7.0.5
Fixed in 7.0.6
Are you affected? Scan for Free

TL;DR

An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-security-saml2-service-provider is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.1 - 5.7.23, 5.8.0 - 5.8.25, 6.0.0 - 6.3.16, 6.4.0 - 6.4.16, 6.5.0 - 6.5.10 and 7.0.0 - 7.0.5.

How to fix this

Upgrade the org.springframework.security:spring-security-saml2-service-provider library to the patch version.