Spring Web Services: SOAP security faults leak Spring Security account state
Moderate severity
GitHub Reviewed
Published
Jun 11, 2026
to the GitHub Advisory Database
•
Updated Aug 21, 2026
Package
Affected versions
>= 5.0.0, <= 5.0.1
>= 4.1.0, <= 4.1.3
>= 4.0.0, <= 4.0.18
>= 3.1.0, <= 3.1.8
Patched versions
5.0.2
4.1.4
Description
Published by the National Vulnerability Database
Jun 11, 2026
Published to the GitHub Advisory Database
Jun 11, 2026
Reviewed
Aug 21, 2026
Last updated
Aug 21, 2026
Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with generic authentication errors. That behavior assists remote attackers in distinguishing valid accounts from invalid ones and inferring lifecycle state.
Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
References