MEDIUMMaven

Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter

Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter

CVE-2026-41008Published 2 months agoUpdated 2 weeks agoSource: OSV

Affected packages

  • org.springframework.security:spring-security-oauth2-authorization-server7.0.0 → 7.0.6

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter | HackTribune