Junglewise Threat Intelligence

CVE-2026-41707: Spring Security DPoP proof JWT replay attack via cache exhaustion

CVE-2026-41707 · Severity: high · CVSS 7.4 · Published 2026-08-25

Vendors: Spring.

Executive brief

Spring Security is a widely-used Java authentication and authorization framework that protects enterprise applications. The DPoP (Demonstrating Proof-of-Possession) JWT validation feature contains a cache-based vulnerability that allows attackers to replay previously captured authentication tokens by flooding the server to evict legitimate entries, potentially bypassing authentication controls and gaining unauthorized access to sensitive application functions.

Technical details

The vulnerability exists in Spring Security's DPoPProofJwtDecoderFactory, which maintains an internal cache of JWT ID claims to prevent replay attacks. However, the cache has a strict size limit, making it susceptible to eviction attacks. An attacker can flood the server with dummy requests to evict legitimate JWT ID entries from the cache, then replay a previously intercepted valid DPoP proof that is no longer cached, bypassing replay protection. The attack requires network access to the Spring Security-protected application and knowledge of a valid DPoP proof captured prior to the attack. Patches are available for affected versions.

Affected products

  • Spring Spring Security 6.5.0 through 6.5.11, 7.0.0 through 7.0.6, and 7.1.0

Timeline

  • 2026-08-25: disclosed

References