CVE-2026-22753Disclosure(vmware / spring_security)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filter chain may fail and its related security components will not be exercised as intended by the application. This can lead to the authentication, authorization, and other security controls being rendered inactive on intended requests.This issue affects Spring Security: from 7.0.0 through 7.0.4.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_security

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
spring_security

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-23: 3Technical Details · 2026-04-23: 204-23
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-22754 ❗ CVE-2026-22753 ❗ CVE-2026-22752 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-4/ https://t.co/cohTXUIqn6

    Post summary

    The post lists three new CVEs affecting Spring products but provides no additional technical, exploit, or remediation details.

    00010159
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-22753 Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, m… https://www.cve.org/CVERecord?id=CVE-2026-22753 ----- Traducción: Vulnerabilidad en … http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑22753, a vulnerability in Spring Security, and links to the CVE record, providing basic technical details but no PoC, exploit, patch, or evidence of active exploitation.

    0000041
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22753 Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, m… https://www.cve.org/CVERecord?id=CVE-2026-22753

    Post summary

    The CVE-2026-22753 entry describes a Spring Security vulnerability involving securityMatchers and PathPatternRequestMatcher.Builder, but offers no PoC, exploit, or patch details.

    00000202
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_security---

Explore more