Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute URL is stored in the cookie and is used without validation as the post-login redirect target. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5. Join the discussion | CVE Database V5 | 06/10/2026, 00:31:51 UTC Added: 06/09/2026, 23:55:50 UTC |
0 Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5. Join the discussion | CVE Database V5 | 06/10/2026, 00:31:51 UTC Added: 06/09/2026, 23:55:46 UTC |
0 An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5. Join the discussion | CVE Database V5 | 06/10/2026, 00:31:51 UTC Added: 06/09/2026, 23:55:46 UTC |
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verification or encryption credentials (verification_credentials and encryption_credentials, respectively). Affected versions: Spring Security 7.0.0 through 7.0.5. Join the discussion | CVE Database V5 | 06/10/2026, 00:31:51 UTC Added: 06/09/2026, 23:55:46 UTC |
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. Affected versions: Spring Security 5.7.0 through 5.7.24; 5.8.0 through 5.8.26; 6.3.0 through 6.3.17; 6.4.0 through 6.4.17; 6.5.0 through 6.5.10. Join the discussion | CVE Database V5 | 06/09/2026, 23:50:07 UTC Added: 06/09/2026, 23:55:56 UTC |
An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5. Join the discussion | CVE Database V5 | 06/09/2026, 23:46:15 UTC Added: 06/09/2026, 23:55:46 UTC |
0 Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then the servlet path is not included and the related authorization rules are not exercised. This can lead to an authorization bypass.This issue affects Spring Security: from 7.0.0 through 7.0.4. Join the discussion | CVE Database V5 | 04/22/2026, 05:32:48 UTC Added: 04/22/2026, 05:46:06 UTC |
0 CVE-2026-22753 is a vulnerability in Spring Security versions 7.0.0 through 7.0.4 where using securityMatchers(String) combined with a PathPatternRequestMatcher. Builder bean to prepend a servlet path can cause requests to bypass the intended security filter chain. This results in authentication, authorization, and other security controls not being applied to those requests as designed, potentially allowing unauthorized actions. The vulnerability has a CVSS score of 7.5, indicating high severity. No official patch or remediation guidance is currently provided by the vendor. Join the discussion | CVE Database V5 | 04/22/2026, 05:20:31 UTC Added: 04/22/2026, 05:46:06 UTC |
0 CVE-2026-22748 is a medium severity vulnerability in Spring Security affecting versions 6.3.0 through 6.3.14, 6.4.0 through 6.4.14, 6.5. Join the discussion | CVE Database V5 | 04/22/2026, 05:15:03 UTC Added: 04/22/2026, 05:46:06 UTC |
0 Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate, this can lead to an attacker impersonating another user. This issue affects Spring Security: from 7.0.0 through 7.0.4. Join the discussion | CVE Database V5 | 04/22/2026, 05:08:41 UTC Added: 04/22/2026, 05:46:06 UTC |
Showing 1 to 10 of 16 results