SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-59277

LOW · CVSS 3.7 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The InetAddressMatchers utility in Spring Security 7.1.0 is vulnerable, allowing for potential misclassification of IP addresses as internal or external, which could lead to improper access controls. Although the severity is rated low, organizations using this version should prioritize patching to mitigate any risk of unauthorized access due to incorrect network classification. Users of Spring Security should assess their exposure and apply updates as necessary to maintain security posture.

CVE
CVE-2026-59277
Severity
LOW
CVSS
3.7
EPSS
0.21%

Original NVD Description

Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or external (public) network. Spring Security 7.1.0

Related CVEs

Other vulnerabilities affecting the same vendor(s)