Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NDefault status
unaffected
6.3.0 (custom)
affected
6.4.0 (custom)
affected
6.5.0 (custom)
affected
7.0.0 (custom)
affected
Description
Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
Product status
6.3.0 (custom)
6.4.0 (custom)
6.5.0 (custom)
7.0.0 (custom)
References
spring.io/security/cve-2026-22748