CVE-2026-40988

An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
References
Link Resource
https://spring.io/security/cve-2026-40988 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) Una aplicación que utiliza spring-security-saml2-service-provider y el binding REDIRECT para el inicio o cierre de sesión de SAML 2.0 puede ser vulnerable a una denegación de servicio por medio de un escritor sin límites que infla la carga útil SAML comprimida en la memoria. Versiones afectadas: Spring Security 5.7.0 hasta 5.7.23; 5.8.0 hasta 5.8.25; 6.3.0 hasta 6.3.16; 6.4.0 hasta 6.4.16; 6.5.0 hasta 6.5.10; 7.0.0 hasta 7.0.5.

12 Jun 2026, 20:38

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:*
First Time Vmware
Vmware spring Security
References () https://spring.io/security/cve-2026-40988 - () https://spring.io/security/cve-2026-40988 - Vendor Advisory

10 Jun 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 00:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-40988

Mitre link : CVE-2026-40988

CVE.ORG link : CVE-2026-40988


JSON object : View

Products Affected

vmware

  • spring_security
CWE
CWE-400

Uncontrolled Resource Consumption