Spring security advisory (AV26-842)

Serial Number: AV26-842
Date: August 21, 2026

As of August 20, 2026, Spring is affected by vulnerabilities in the following products:

  • Spring AI
    • Prior to or equal to 2.0.0
    • Prior to or equal to 1.0.9
    • Prior to or equal to 1.1.8
  • Spring Security
    • Multiple versions
  • Spring Cloud Config
    • Multiple versions
  • Spring Data REST
    • Multiple versions
  • Spring Cloud Gateway
    • Multiple versions
  • Spring Cloud Commons
    • Multiple versions
  • Spring for GraphQL
    • Multiple versions
  • Spring Integration
    • Multiple versions
  • Spring Authorization Server
    • Prior to or equal to 1.5.8
    • Prior to or equal to 1.4.11

The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.

Date modified: