CVE-2026-22752

Updated on 16 Jul 2026

Severity

9.0 Critical severity

Details

CVSS score
9.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Overview

About vulnerability

Spring Authorization Server Dynamic Client Registration endpoints perform insufficient validation of certain client metadata fields when explicitly enabled.

An attacker possessing a valid Initial Access Token can dynamically register a malicious client with crafted metadata. Depending on the metadata provided and the Authorization Server’s configuration, this can lead to Stored Cross-Site Scripting (XSS), Privilege Escalation, or Server-Side Request Forgery (SSRF).

Details

Affected product:
Spring
Affected packages:
Spring Boot @ 3.3.13 (+248 more)

Fixes