CVE-2026-59316

HIGH CVSS 3.1: 8.2 EPSS 0.18%
Updated Sep 01, 2026
Broadcom
Parameter Value
CVSS 8.2 (HIGH)
Affected Versions 1.4.0 — 1.5.9
Fixed In 1.4.12
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Broadcom
Public PoC No

Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page presented to the end user. Spring Authorization Server 1.5.0 - 1.5.8 Spring Authorization Server 1.4.0 - 1.4.11

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Broadcom Spring_Authorization_Server
cpe:2.3:a:broadcom:spring_authorization_server:*:*:*:*:*:*:*:*
1.4.0 1.4.12
Broadcom Spring_Authorization_Server
cpe:2.3:a:broadcom:spring_authorization_server:*:*:*:*:*:*:*:*
1.5.0 1.5.9