CVE-2026-22751

ADVISORY - github

Summary

Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

EPSS Score: 0.00041 (0.121)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Time-of-check Time-of-use (TOCTOU) Race Condition

ADVISORY - github

Time-of-check Time-of-use (TOCTOU) Race Condition


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in