GHSA-8crv-49fr-2h6j · Severity: high · Ecosystem: maven — Spring Security and Spring Framework may not recognize certain paths that should be protected
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching mechanisms, for example with regards to space trimming in path segments, can lead Spring Security to not recognize certain paths as not protected that are in fact mapped to Spring MVC controllers that should be protected. The problem is compounded by the fact that the Spring Framework provides richer features with regards to pattern matching as well as by the fact that pattern matching in each Spring Security and the Spring Framework can easily be customized creating additional differences.
Conclusion & alert: CVE-2016-5007 is rated Moderate Risk (42.7/100): CVSS High severity, with low exploitation likelihood (EPSS 0.15%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-10-15 | 0.34% | 0.15% | -0.18% |
| 2 | 2025-03-30 | 1.16% | 0.34% | -0.82% |
| 3 | 2025-03-29 | — | 1.16% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.0 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-8crv-49fr-2h6j · Severity: high · Ecosystem: maven — Spring Security and Spring Framework may not recognize certain paths that should be protected
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2016-5007 not yet assigned priority: Debian including 1 source packages (libspring-java), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2016-5007 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2016-5007 |
ubuntu
|
medium | CVE-2016-5007 medium priority: Ubuntu including 1 source packages (libspring-java), 24 status rows across 24 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, precise, questing, trusty, upstream, wily, xenial, yakkety, zesty): not-affected 16, ignored 5, needed 2, needs-triage 1. | https://ubuntu.com/security/CVE-2016-5007 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| pivotal_software | spring_framework | 3.2.0 | cpe:2.3:a:pivotal_software:spring_framework:3.2.0:*:*:*:*:*:*:* |
| pivotal_software | spring_framework | 4.0.0 | cpe:2.3:a:pivotal_software:spring_framework:4.0.0:*:*:*:*:*:*:* |
| pivotal_software | spring_framework | 4.1.0 | cpe:2.3:a:pivotal_software:spring_framework:4.1.0:*:*:*:*:*:*:* |
| pivotal_software | spring_framework | 4.2.0 | cpe:2.3:a:pivotal_software:spring_framework:4.2.0:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.1 | cpe:2.3:a:vmware:spring_framework:3.2.1:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.2 | cpe:2.3:a:vmware:spring_framework:3.2.2:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.3 | cpe:2.3:a:vmware:spring_framework:3.2.3:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.4 | cpe:2.3:a:vmware:spring_framework:3.2.4:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.5 | cpe:2.3:a:vmware:spring_framework:3.2.5:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.6 | cpe:2.3:a:vmware:spring_framework:3.2.6:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.7 | cpe:2.3:a:vmware:spring_framework:3.2.7:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.8 | cpe:2.3:a:vmware:spring_framework:3.2.8:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.9 | cpe:2.3:a:vmware:spring_framework:3.2.9:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.10 | cpe:2.3:a:vmware:spring_framework:3.2.10:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.11 | cpe:2.3:a:vmware:spring_framework:3.2.11:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.12 | cpe:2.3:a:vmware:spring_framework:3.2.12:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.13 | cpe:2.3:a:vmware:spring_framework:3.2.13:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.14 | cpe:2.3:a:vmware:spring_framework:3.2.14:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.15 | cpe:2.3:a:vmware:spring_framework:3.2.15:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.16 | cpe:2.3:a:vmware:spring_framework:3.2.16:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.17 | cpe:2.3:a:vmware:spring_framework:3.2.17:*:*:*:*:*:*:* |
| vmware | spring_framework | 3.2.18 | cpe:2.3:a:vmware:spring_framework:3.2.18:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.1 | cpe:2.3:a:vmware:spring_framework:4.0.1:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.2 | cpe:2.3:a:vmware:spring_framework:4.0.2:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.3 | cpe:2.3:a:vmware:spring_framework:4.0.3:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.4 | cpe:2.3:a:vmware:spring_framework:4.0.4:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.5 | cpe:2.3:a:vmware:spring_framework:4.0.5:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.6 | cpe:2.3:a:vmware:spring_framework:4.0.6:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.7 | cpe:2.3:a:vmware:spring_framework:4.0.7:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.8 | cpe:2.3:a:vmware:spring_framework:4.0.8:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.0.9 | cpe:2.3:a:vmware:spring_framework:4.0.9:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.1.1 | cpe:2.3:a:vmware:spring_framework:4.1.1:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.1.2 | cpe:2.3:a:vmware:spring_framework:4.1.2:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.1.3 | cpe:2.3:a:vmware:spring_framework:4.1.3:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.1.4 | cpe:2.3:a:vmware:spring_framework:4.1.4:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.1.5 | cpe:2.3:a:vmware:spring_framework:4.1.5:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.1.6 | cpe:2.3:a:vmware:spring_framework:4.1.6:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.1.7 | cpe:2.3:a:vmware:spring_framework:4.1.7:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.1.8 | cpe:2.3:a:vmware:spring_framework:4.1.8:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.1.9 | cpe:2.3:a:vmware:spring_framework:4.1.9:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.2.1 | cpe:2.3:a:vmware:spring_framework:4.2.1:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.2.2 | cpe:2.3:a:vmware:spring_framework:4.2.2:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.2.3 | cpe:2.3:a:vmware:spring_framework:4.2.3:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.2.4 | cpe:2.3:a:vmware:spring_framework:4.2.4:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.2.5 | cpe:2.3:a:vmware:spring_framework:4.2.5:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.2.6 | cpe:2.3:a:vmware:spring_framework:4.2.6:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.2.7 | cpe:2.3:a:vmware:spring_framework:4.2.7:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.2.8 | cpe:2.3:a:vmware:spring_framework:4.2.8:*:*:*:*:*:*:* |
| vmware | spring_framework | 4.2.9 | cpe:2.3:a:vmware:spring_framework:4.2.9:*:*:*:*:*:*:* |
| vmware | spring_security | 3.2.0 | cpe:2.3:a:vmware:spring_security:3.2.0:*:*:*:*:*:*:* |
| vmware | spring_security | 3.2.1 | cpe:2.3:a:vmware:spring_security:3.2.1:*:*:*:*:*:*:* |
| vmware | spring_security | 3.2.2 | cpe:2.3:a:vmware:spring_security:3.2.2:*:*:*:*:*:*:* |
| vmware | spring_security | 3.2.3 | cpe:2.3:a:vmware:spring_security:3.2.3:*:*:*:*:*:*:* |
| vmware | spring_security | 3.2.4 | cpe:2.3:a:vmware:spring_security:3.2.4:*:*:*:*:*:*:* |
| vmware | spring_security | 3.2.5 | cpe:2.3:a:vmware:spring_security:3.2.5:*:*:*:*:*:*:* |
| vmware | spring_security | 3.2.6 | cpe:2.3:a:vmware:spring_security:3.2.6:*:*:*:*:*:*:* |
| vmware | spring_security | 3.2.7 | cpe:2.3:a:vmware:spring_security:3.2.7:*:*:*:*:*:*:* |
| vmware | spring_security | 3.2.8 | cpe:2.3:a:vmware:spring_security:3.2.8:*:*:*:*:*:*:* |
| vmware | spring_security | 3.2.9 | cpe:2.3:a:vmware:spring_security:3.2.9:*:*:*:*:*:*:* |
| vmware | spring_security | 3.2.10 | cpe:2.3:a:vmware:spring_security:3.2.10:*:*:*:*:*:*:* |
| vmware | spring_security | 4.0.0 | cpe:2.3:a:vmware:spring_security:4.0.0:*:*:*:*:*:*:* |
| vmware | spring_security | 4.0.1 | cpe:2.3:a:vmware:spring_security:4.0.1:*:*:*:*:*:*:* |
| vmware | spring_security | 4.0.2 | cpe:2.3:a:vmware:spring_security:4.0.2:*:*:*:*:*:*:* |
| vmware | spring_security | 4.0.3 | cpe:2.3:a:vmware:spring_security:4.0.3:*:*:*:*:*:*:* |
| vmware | spring_security | 4.0.4 | cpe:2.3:a:vmware:spring_security:4.0.4:*:*:*:*:*:*:* |
| vmware | spring_security | 4.1.0 | cpe:2.3:a:vmware:spring_security:4.1.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html | |
| http://www.securityfocus.com/bid/91687 | Third Party Advisory VDB Entry |
| https://pivotal.io/security/cve-2016-5007 | Vendor Advisory |
| https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html |