CVE-2026-22751
ADVISORY - githubSummary
Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
EPSS Score: 0.00041 (0.121)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Time-of-check Time-of-use (TOCTOU) Race Condition
ADVISORY - github
Time-of-check Time-of-use (TOCTOU) Race Condition
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in