CVE-2026-22732 | VMware Spring Security up to 7.0.3 HTTP Response Header direct request (WID-SEC-2026-0797)
A vulnerability has been found in VMware Spring Security up to 7.0.3 and classified as critical. The impacted element is an unknown function of the component HTTP Response Header Handler. Performing a manipulation results in direct request.
This vulnerability was named CVE-2026-22732. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.