Spring Security
97%
Total Score
99
83
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-22960 spring-security-core is vulnerable to Open Redirect in versions 7.0.0 - 7.0.5. | 7.0.0 - 7.0.5 | Medium |
AIKIDO-2026-458467 spring-security-core is vulnerable to Deserialization of Untrusted Data in versions 7.0.0 - 7.0.5. | 7.0.0 - 7.0.5 | High |
CVE-2026-22746 org.springframework.security:spring-security-core is vulnerable to Observable Timing Discrepancy in versions 5.7.0 - 5.7.22, 5.8.0 - 5.8.24, 6.3.0 - 6.3.15, 6.4.0 - 6.4.15, 6.5.0 - 6.5.9 and 7.0.0 - 7.0.4. | 5.7.0 - 5.7.225.8.0 - 5.8.246.3.0 - 6.3.15 +3 more | Low |
CVE-2026-22751 org.springframework.security:spring-security-core is vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in versions 6.5.0 - 6.5.10, 7.0.3 - 7.0.5 and 6.4.0 - 6.4.13. | 6.4.0 - 6.4.136.5.0 - 6.5.107.0.3 - 7.0.5 | Medium |
CVE-2025-22234 org.springframework.security:spring-security-core is vulnerable to Observable Timing Discrepancy in versions 6.3.8 - 6.3.8 and 6.4.4 - 6.4.4. | 6.3.8 - 6.3.86.4.4 - 6.4.4 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework.security:spring-security-crypto Version 7.1.0 | — | — |
org.springframework:spring-aop Version 7.0.8 | — | — |
org.springframework:spring-beans Version 7.0.8 | — | — |
org.springframework:spring-context Version 7.0.8 | — | — |
org.springframework:spring-core Version 7.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant