# CVE-2026-41707

## Summary

- **CVE ID:** CVE-2026-41707
- **Severity:** HIGH
- **CVSS Score:** 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-294
- **Published:** Aug 25, 2026
- **Last Modified:** Aug 27, 2026

## Description

Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs.
Spring Security 7.1.0
Spring Security 7.0.0 - 7.0.6
Spring Security 6.5.0 - 6.5.11

## Affected Products

- Spring — Spring Security (7.1.0)
- Spring — Spring Security (7.0.0)
- Spring — Spring Security (6.5.0)

## References

- [CNA](https://spring.io/security/cve-2026-41707)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 16.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._