CVE-2026-22748 — Spring Security: From Vulnerability

CVE-2026-22748 — Spring Security: From Vulnerability

CVE-2026-22748 — Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 t

What This Means For You

  • If your environment is affected by this vulnerability type, review your exposure and prioritize patching based on your environment. Monitor vendor advisories for CVE-2026-22748 updates and patches.

Related ATT&CK Techniques

🛡️ Detection Rules

1 rule · 6 SIEM formats

1 detection rule auto-generated for this incident, mapped to MITRE ATT&CK. Sigma YAML is free — export to any SIEM format via the Intel Bot.

high T1190 Initial Access

CVE-2026-22748 - Spring Security JWT Decoder Vulnerability

Sigma YAML — free preview
✓ Sigma · Splunk SPL Sentinel KQL Elastic QRadar AQL Wazuh Export via Bot →

Indicators of Compromise

IDTypeIndicator
CVE-2026-22748 vulnerability CVE-2026-22748
Source & Attribution
Source PlatformNVD
ChannelNational Vulnerability Database
PublishedApril 22, 2026 at 09:16 UTC

This content was curated and summarized by Shimi's Cyber World for informational purposes. It is not copied or republished in full. All intellectual property rights remain with the original author and source.

Believe this infringes your rights? Submit a takedown request.

Related Posts

CVE-2026-6840 — Missing bounds validation for operator could allow out of

CVE-2026-6840 — Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected version is prior to commit 1.30.0.

vulnerabilityCVEmedium-severitycwe-129
/SCW Vulnerability Desk /MEDIUM /5.5 /⚑ 2 IOCs /⚙ 1 Sigma

CVE-2026-6839 — Improper validation of STRING tensor offsets could allows

CVE-2026-6839 — Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung...

vulnerabilityCVEmedium-severitycwe-1284
/SCW Vulnerability Desk /MEDIUM /6.6 /⚑ 2 IOCs /⚙ 1 Sigma

CVE-2026-41667 — Integer Overflow

CVE-2026-41667 — Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes. Affected...

vulnerabilityCVEmedium-severityinteger-overflowcwe-190
/SCW Vulnerability Desk /MEDIUM /6.6 /⚑ 2 IOCs /⚙ 1 Sigma