Junglewise Threat Intelligence

CVE-2026-41003: VMware Spring Security XSS in RelyingPartyRegistration

CVE-2026-41003 · Severity: high · CVSS 7.6 · Published 2026-06-10

Technologies: VMware Spring Security. Vendors: Spring, VMware.

Executive brief

A vulnerability in Spring Security's SAML2 component could allow an attacker to execute malicious code within a user's browser. This occurs when the system generates HTML forms using data that an attacker has influenced, such as SAML registration details. If exploited, this could lead to the theft of sensitive user information or unauthorized actions performed on behalf of the user.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Spring Security SAML2 Service Provider. The root cause is the improper neutralization of input within the RelyingPartyRegistration component when generating HTML forms via Spring Security filters. Specifically, the FormPostRedirectStrategy failed to properly handle or encode values, allowing an attacker who can influence registration metadata to inject malicious scripts into hidden form inputs. An attacker with low privileges could leverage this to execute arbitrary JavaScript in the context of a victim's browser session. Patches are available in versions 6.5.11 and 7.0.6.

Affected products

  • Spring Spring Security SAML2 Service Provider 5.7.0 to 5.7.23, 5.8.0 to 5.8.25, 6.3.0 to 6.3.16, 6.4.0 to 6.4.16, 6.5.0 to 6.5.10, 7.0.0 to 7.0.5

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory
  • 2026-06-09: patched: Release of version 6.5.11

References

Related threats