Org.springframework.security.oauth:spring-security-oauth2
5 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Org.springframework.security.oauth:spring-security-oauth2, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Org.springframework.security.oauth:spring-security-oauth2 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 5 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High1
- Medium2
Latest CVEs
The 5 most recently published vulnerabilities affecting Org.springframework.security.oauth:spring-security-oauth2.
- CVE-2022-22969<Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) attack via the initiation of the Authorization Re...6.5
- CVE-2019-3778Open Redirect in spring-security-oauth26.5
- CVE-2018-15758Privilege Escalation in spring-security-oauth29.6
- CVE-2018-1260Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A mali...9.8
- CVE-2016-4977When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which ena...8.8
Product grouping is registry-driven, with AI assist and human review. How it works