Spring Security's DPoPProofJwtDecoderFactory contains a...
High severity
Unreviewed
Published
Aug 26, 2026
to the GitHub Advisory Database
•
Updated Aug 26, 2026
Description
Published by the National Vulnerability Database
Aug 25, 2026
Published to the GitHub Advisory Database
Aug 26, 2026
Last updated
Aug 26, 2026
Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Security 6.5.0 - 6.5.11
References