{"id":"GHSA-cvc6-q2cp-2xhw","summary":"Spring Security has Potential Security Misconfiguration when Using withIssuerLocation","details":"Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator\u003cJwt\u003e separately, for example by calling setJwtValidator. This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.","aliases":["CVE-2026-22748"],"modified":"2026-07-17T21:13:06.117268288Z","published":"2026-04-22T06:30:29Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-29T20:48:38Z","nvd_published_at":"2026-04-22T06:16:04Z","cwe_ids":["CWE-20"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22748"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-security"},{"type":"WEB","url":"https://spring.io/security/cve-2026-22748"}],"affected":[{"package":{"name":"org.springframework.security:spring-security-oauth2-jose","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-oauth2-jose"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.3.0"},{"last_affected":"6.3.14"}]}],"versions":["6.3.0","6.3.1","6.3.10","6.3.2","6.3.3","6.3.4","6.3.5","6.3.6","6.3.7","6.3.8","6.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-cvc6-q2cp-2xhw/GHSA-cvc6-q2cp-2xhw.json"}},{"package":{"name":"org.springframework.security:spring-security-oauth2-jose","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-oauth2-jose"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.4.0"},{"last_affected":"6.4.14"}]}],"versions":["6.4.0","6.4.1","6.4.10","6.4.11","6.4.12","6.4.13","6.4.2","6.4.3","6.4.4","6.4.5","6.4.6","6.4.7","6.4.8","6.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-cvc6-q2cp-2xhw/GHSA-cvc6-q2cp-2xhw.json"}},{"package":{"name":"org.springframework.security:spring-security-oauth2-jose","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-oauth2-jose"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.5.0"},{"fixed":"6.5.10"}]}],"versions":["6.5.0","6.5.1","6.5.2","6.5.3","6.5.4","6.5.5","6.5.6","6.5.7","6.5.8","6.5.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 6.5.9","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-cvc6-q2cp-2xhw/GHSA-cvc6-q2cp-2xhw.json"}},{"package":{"name":"org.springframework.security:spring-security-oauth2-jose","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-oauth2-jose"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.0.5"}]}],"versions":["7.0.0","7.0.1","7.0.2","7.0.3","7.0.4"],"database_specific":{"last_known_affected_version_range":"\u003c= 7.0.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-cvc6-q2cp-2xhw/GHSA-cvc6-q2cp-2xhw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}